A vehicle network authentication method based on PUF and fuzzy extractor
By introducing multi-TA models and fuzzy extractors in the Internet of Vehicles, the problems of high overhead and environmental noise impact of resource-limited devices in Internet of Vehicles authentication are solved, efficient and secure communication authentication is achieved, and single point failure is avoided.
Patent Information
- Application Number
- CN202410435671.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-11
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-04-11
AI Technical Summary
Existing Internet of Vehicles authentication protocols have high efficiency and resource overhead in resource-limited devices, and the PUF response is easily affected by environmental noise, posing a high risk of single-point failure.
A multi-TA model based on PUF and fuzzy extractor is adopted, combined with vehicle network equipment VE, roadside unit RSU and trusted center TA. Through the initialization, registration, authentication and key exchange and key update stages, the fuzzy extractor is used to solve the noise impact and avoid single point failure.
It reduces computing and communication overheads while ensuring security, improves the efficiency and reliability of vehicle network communications, and avoids the risk of single point failure.
Smart Images

Figure CN118250693B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle networking, and in particular to a vehicle networking authentication method based on PUF and a fuzzy extractor. Background Art
[0002] As an extension of the Internet of Things (IoT) in the transportation sector, the Internet of Vehicles (IoV) can greatly facilitate vehicle management and route planning. With the increasing popularity of IoV and the increasing number of vehicles connected to the IoV network, the security and privacy of IoV systems need to be guaranteed, while also placing higher demands on communication efficiency and resource consumption.
[0003] Traditional symmetric or asymmetric encryption algorithms typically require higher processing power to ensure authentication and communication security. However, in resource-limited connected vehicle devices, authentication protocols have higher requirements for efficiency and resource overhead. This means that compared to traditional authentication protocols, connected vehicle authentication protocols must achieve authentication functions with the same or higher efficiency and accuracy while using fewer resources. PUFs are a perfect match for this requirement.
[0004] In recent years, various lightweight authentication and key exchange protocols have been proposed to ensure the security and efficiency of IoV communications. For example, some scholars have pointed out some security issues in the IoV environment, such as susceptibility to eavesdropping, replay, and impersonation attacks, and the fact that most existing protocols are based on high communication and computing rates and are not suitable for IoV environments. Based on this, a lightweight privacy-preserving authentication protocol based on PUF for IoV was proposed, which provides efficient and secure communication (S. M. Awais, W. Yucheng, K. Mahmood, M. W. Akram, S. Hussain, A. K. Das, and Y. Park, “Puf-based privacy-preserving simultaneous authentication among multiple vehicles in a van,”
[0005] IEEE Transactions on Vehicular Technology, pp. 1–14, 2023.).
[0006] Some researchers have also proposed a two-factor authentication protocol. This protocol combines passwords and PUFs to achieve two-factor security. Users can successfully log in using a device with a built-in PUF or a registered password. This protects user privacy while resisting desynchronization attacks, thereby achieving secure communication (Q. Jiang, X. Zhang, N. Zhang, Y. Tian, X. Ma, and J. Ma, “Two-factor authentication protocol using physical unclonable function foriov,” 2019 IEEE / CIC International Conference on Communications in China (ICCC), pp. 195–200, 2019).
[0007] Chinese patent CN114390474A discloses a lightweight two-factor bidirectional anonymous authentication system and method for the Internet of Vehicles based on BS-PUF. This scheme uses random pseudonyms to implement identity information privacy protection and constructs an authentication protocol based on elliptic curves, effectively reducing the computational workload of Internet of Vehicles nodes and achieving lightweight, low-latency authentication.
[0008] However, existing technical solutions still have shortcomings. For example, due to environmental and conditional influences, the PUF's response to the same challenge may vary slightly. Therefore, it is necessary to consider the impact of noise during the authentication process. However, most existing technical solutions do not take appropriate measures to address the impact of noise in the PUF response. In addition, the design of most existing solutions relies on a single trusted authority (TA), which may create a series of risks (such as single points of failure).
[0009] In summary, the design of an Internet of Vehicles authentication method based on PUF and fuzzy extractor is helpful in solving the problem of secure communication in the Internet of Vehicles. Summary of the Invention
[0010] The purpose of the present invention is to provide a vehicle network authentication method based on PUF and fuzzy extractor to overcome the technical problems existing in existing methods in mechanical fault diagnosis.
[0011] The first main aspect of the present invention is to propose a vehicle network authentication method based on PUF and fuzzy extractor, which includes constructing an authentication and key exchange protocol based on PUF and fuzzy extractor. The construction of the protocol involves at least three components: vehicle network device VE, roadside unit RSU, and trusted center TA;
[0012] In the Internet of Vehicles authentication system of the present invention, the Internet of Vehicles equipment VE (Vehicle Equipment), roadside unit RSU (Road Side Unit) and trusted center TA (Trusted Authority) jointly construct an authentication and key exchange protocol based on PUF and fuzzy extractor.
[0013] Vehicle-to-vehicle (VE) devices include on-board devices installed on vehicles, such as on-board communication modules, sensors, etc. Their main function is to collect real-time data from vehicles, such as location, speed, driving status, etc., and transmit it to other vehicles or roadside units (RSUs).
[0014] Or receive information from other vehicles or RSUs, such as traffic conditions, safety warnings, etc., and provide it to the driver or the vehicle's autonomous driving system.
[0015] Furthermore, the connected vehicle (VE) device communicates with other vehicles and infrastructure via vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication technologies (e.g., C-V2X). In this invention, the connected vehicle (VE) device participates in the identity authentication and security trust mechanism of the connected vehicle, ensuring communication security and vehicle identity authenticity.
[0016] Roadside units (RSUs) are fixed devices deployed alongside roads. Acting as a communication intermediary between vehicles and transportation infrastructure, RSUs receive and forward vehicle information, as well as provide information on road conditions and traffic signals. They collect information on road and traffic conditions and communicate with terminals such as traffic lights and electronic signs via a communications network, enabling vehicle-road connectivity.
[0017] Roadside units (RSUs) can also assist vehicles in driving, providing vehicle-road collaborative services such as traffic light reminders, green wave passes, and road traffic information prompts. In the present invention, roadside units (RSUs) participate in the identity authentication process of the Internet of Vehicles, ensuring communication security with vehicles and data accuracy.
[0018] Trusted Authority (TA): The Trusted Authority (TA) is the authoritative body within the connected vehicle system, responsible for establishing and maintaining a secure trust system for the entire network. The TA generates and distributes digital certificates, providing identity authentication services for vehicles and infrastructure, ensuring the authenticity and trustworthiness of both communicating parties. It manages the lifecycle of keys and certificates, including issuance, renewal, and revocation. It establishes and maintains a secure root of trust for the connected vehicle, providing the foundation for secure communications between vehicles and the cloud, between vehicles, and between vehicles and the road. In the event of a security incident, such as a vehicle sending a malicious message, the TA is able to trace the true identity of the specific vehicle, thereby maintaining the security and reliability of the network.
[0019] In this invention, the trusted center (TA) is a multi-TA structure, with a master TA responsible for device registration and multiple sub-TAs responsible for assisting communication nodes in completing the authentication process. Furthermore, the master TA manages all sub-TAs, each of which is responsible for multiple RSUs within its scope of authority. RSUs are fixed, while VEs are mobile. VEs can communicate with any RSU, while RSUs can only access sub-TAs in other areas under specific conditions. These specific conditions include: the sub-TA responsible for the RSU's area experiencing a single point of failure, preventing normal access to sub-TAs to assist in completing the authentication process.
[0020] As a further preferred solution, in the present invention, the protocol is divided into at least four stages: an initialization stage, a registration stage, an authentication and key exchange stage, and a key update stage; the initialization stage includes: the total TA randomly selects a large prime number q; the total TA randomly selects an additive group with an order of q and a generator of P; the sub-TA obtains all communication node registration data stored in the total TA from a secure channel; and the registration stage includes the registration of VE and the registration of RSU; the authentication and key exchange stage includes communication authentication between VE and RSU, and communication authentication between VE and VE; the key update stage includes communication authentication between VE and RSU, and communication authentication between VE and VE.
[0021] According to the second main aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored. When the program is executed, the vehicle network authentication method based on PUF and fuzzy extractor as described above is implemented.
[0022] Based on the third main aspect of the present invention, a hardware device for vehicle network authentication includes a data storage device, a processor, and a computer program stored in the data storage device and executable on the processor. The device is characterized in that when the processor executes the program, the vehicle network authentication method based on PUF and fuzzy extractor as described above is implemented.
[0023] Advantages and beneficial effects of the present invention:
[0024] Beneficial effects of the present invention: The present invention proposes a vehicle network authentication method based on PUF and fuzzy extractor, which is used for secure communication between VE and RSU and between VE and VE in the vehicle network; the present invention uses a multi-TA model to manage and store a series of information of vehicle network devices to avoid single point failure problems in the vehicle network system; in addition, the present invention uses PUF technology and fuzzy extractor technology, and utilizes the fuzzy extractor to solve the problem that PUF signals are easily affected by environmental changes and noise, which can effectively reduce computing overhead and communication overhead while ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, without paying any creative work, other drawings obtained based on these drawings still fall within the scope of the present invention.
[0026] Figure 1 It is a flowchart of the VE registration process in the total TA in an example of this method.
[0027] Figure 2 This is a flowchart of the RSU registration process in the total TA in an example of this method.
[0028] Figure 3 This is a flowchart of the identity authentication and key exchange process when VE initiates communication with RSU in an example of this method.
[0029] Figure 4 It is a flowchart of the identity authentication and key exchange process during the process of VE to VE initiating communication in an example of this method. DETAILED DESCRIPTION
[0030] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings so that the objects, features and advantages of the present invention can be more clearly understood. It should be understood that the embodiments shown in the accompanying drawings are not intended to limit the scope of the present invention, but are only intended to illustrate the essential spirit of the technical solution of the present invention.
[0031] In the following description, for the purpose of illustrating the various disclosed embodiments, certain specific details are set forth in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the relevant art will recognize that the embodiments may be practiced without one or more of these specific details. In other cases, well-known devices, structures, and techniques associated with this application may not be shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.
[0032] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of "in one embodiment" or "in an embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any manner in one or more embodiments.
[0033] Example 1:
[0034] See Figures 1 to 4The present invention provides a vehicle network authentication method based on PUF and based on PUF and fuzzy extractor, including a registration stage and an identity authentication and key exchange stage.
[0035] Registration phase, see Figure 1 and Figure 2 The registration phase is divided into VE registration and RSU registration, where VE registration includes the following four steps:
[0036] Step 1: VE sends its identity information ID to the general TA through a secure channel.
[0037] Step 2: When the total TA receives the registration request from VE, it generates a 128-bit random number SK as the first key of VE, and then calculates And send C to VE through a secure channel.
[0038] Step 3: After receiving C from the total TA, VE calculates R = PUF(C), then VE stores SK and sends R to the total TA through a secure channel.
[0039] Step 4: After receiving R, the total TA calculates Gen(R) = (K, P) and stores ID, K, P, SK, and R in the database.
[0040] RSU registration includes the following four steps:
[0041] Step 1: RSU sends its identity information ID to the general TA through a secure channel.
[0042] Step 2: When the total TA receives the registration request from the RSU, it selects a random number As the private key of RSU, calculate P RSU =s RSU ·P obtains the public key of RSU, and then RSU ,P RSU ) is sent to RSU through a secure channel.
[0043] Step 3: Receive (s RSU ,P RSU ), RSU calculates Key=PUF(s RSU ) and then (s RSU ,P RSU ) is stored in the database, and then the Key is sent to the total TA.
[0044] Step 4: After receiving the message from RSU, the TA will RSU ,Key,P RSU Stored in the database.
[0045] During the identity authentication and key exchange phase, identity authentication must be completed before the Internet of Vehicles devices can communicate. During the identity authentication process, authentication, key exchange, and key update processes must be completed. This phase includes communication between VE and RSU and communication between VE and VE.
[0046] VE initiates communication with RSU, see Figure 3 , the identity authentication and key exchange process includes the following steps:
[0047] Step 1: VE calculates PID A,i =ID A ||SK A,i ||T1 and generate a timestamp T1, then set the PID A,i and T1 are sent to RSU.
[0048] Step 2: When RSU receives the message from VE, it first checks |T now -T1|<ΔT is established. If established, RSU generates a timestamp T2 and calculates m=hash(P RSU ||T2), then PID A,i , ID RSU , T1, T2, m are sent to the sub-TA.
[0049] Step 3: When the sub-TA receives the message from the RSU, it first checks the freshness of the message. After successful verification, the sub-TA looks up the ID RSU Does it exist in the database? If so, calculate and verify the message m to authenticate the legitimacy of the RSU. After authenticating the legitimacy of the RSU, calculate and check the PID for each TA. A,i If it exists, calculate Then generate timestamp T3, calculate Finally, P A,i ,C A,i ,m1,T3 is sent to RSU.
[0050] Step 4: When the RSU receives the message from the TA, it first checks |T now -T3|<ΔT is established. If so, RSU generates a timestamp T4 and then A,i , P A,i , T3, T4, m1 is sent to VE.
[0051] Step 5: When VE receives the message from RSU, it first checks the freshness of the message. After successful verification, the vehicle uses its own PUF to calculate the response, and then uses the fuzzy extractor regeneration function to calculate K A,i =Rep(R A,i ,P A,i) to get K A,i ,calculate Verify m1. If the verification is successful, VE generates a timestamp T5 and then calculates R A,i+1 =PUF(C A,i+1 ), then, using the data obtained from the above process, VE is calculated Then, m2, m3, and T5 are sent to the RSU.
[0052] Step 6: When RSU receives the message from VE, it first checks |T now -T5|<ΔT. If so, the RSU generates a timestamp T6 and then sends m2, m3, T5, and T6 to the sub-TA.
[0053] Step 7: When the sub-TA receives the message from the RSU, it first checks the freshness of the message. After successful verification, the sub-TA calculates Reusing hash(K A,i ) Decrypt m3 to get R A,i+1 , then calculate Verify m2. If the verification is successful, use the decrypted R A,i+1 and fuzzy extractor generation function calculation (K A,i+1 ,P A,i+1 )=Gen(R A,i+1 ). Then the TA uses the corresponding RSU to store the P in the memory. RSU right Encrypt Then generate timestamp T7 and send S,T7 to RSU. A,i ,P A,i ,SK A,i And store K A,i+1 ,P A,i+1 ,SK A,i+1 Update completed.
[0054] Step 8: When the RSU receives the message from the TA, it first checks |T now -T7|<ΔT is established. If established, RSU uses P RSU Decrypt S to get Then calculate Key = PUF(s RSU ), and then use the calculated Key to perform an XOR operation to obtain the session key K for this round A,i .
[0055] VE deletes all parameters stored during the authentication process and stores SK A,i+1 Update completed.
[0056] VE initiates communication with VE, see Figure 4 , the identity authentication and key exchange process includes the following steps:
[0057] Step 1: VE A Calculating PID A,i =ID A ||SK A,i ||T1 and generate a timestamp T1, then set the PID A,i , the VE with which you want to communicate B PID sent out B,i and timestamp T B , and T1 is sent to RSU.
[0058] Step 2: When RSU receives VE A After receiving the message, first check |T now -T1|<ΔT is established. If established, RSU generates a timestamp T2 and calculates m=hash(P RSU ||T2), then PID A,i ,PID B,i ,ID RSU ,m,T B ,T1,T2 are sent to the sub-TA.
[0059] Step 3: When the TA receives the message from the RSU, it first calculates the message based on the data stored in the database and the T B Check if the PID can be calculated B,i , thereby checking VE B If the verification fails, the TA rejects the authentication request, otherwise, the authentication and key exchange phase between VE and RSU is executed from step 3 to step 7 for VE. A If VE A After authentication, the TA generates a timestamp T3 and calculates Then, C B,i ,P B,i ,m1,m2,T3 are sent to RSU.
[0060] Step 4: When the RSU receives the message from the TA, it first checks |T now -T3|<ΔT is established. If so, RSU generates a timestamp T4 and then B,i ,P B,i ,m1,m2,T3,T4 sent to VE A .
[0061] Step 5: When VE AAfter receiving the message from RSU, the VE first checks the freshness of the message. A Generate a timestamp T5, and then use the K obtained in the previous step to A,i After hashing, decrypting m2 yields and Next, we use the R obtained in the previous step A,i Perform XOR operation to get K B,i , then calculate Verify m1. After verification, VE A calculate Then, C B,i ,P B,i ,m3,m4,T5 sent to VE B .
[0062] Step 6: When VE B Receive VE A After receiving the message, the freshness of the message is checked first. After successful verification, VE B Calculate R using PUF and fuzzy extractor regeneration function B,i =PUF(C B,i ) and K B,i =Rep(R B,i ,P B,i ), then calculate hash(K B,i ) Decrypt m4 to get Next, VE B Use the obtained R B,i Perform XOR operation to get K A,i Then, calculate To verify m3. After verification, VE B calculate Get this round and VE A The session key S.
[0063] Step 7: VE A Delete a series of parameters generated during the authentication process, only SK A,i+1 Stored in memory to complete the key update. VE B Generate a timestamp T6, and then calculate and Then use PUF to calculate R B,i+1 =PUF(C B,i+1 ). Then, calculate and And send m5, m6, T6 to RSU. At the same time, delete all intermediate parameters and only store SK B,i+1 Key update completed.
[0064] Step 2: When RSU receives VE B After receiving the message, first check |T now -T6|<ΔT. If so, the RSU generates a timestamp T7 and sends m5, m6, T6, and T7 to the sub-TA.
[0065] Step 3: When the sub-TA receives the message from the RSU, it first checks the freshness of the message. After verification, the sub-TA decrypts m6 to obtain m3, R B,i+1 , then calculate Then use SK B,i+1 calculate To verify m5. If the verification is successful, use the fuzzy extractor to generate the function calculation (K B,i+1 ,P B,i+1 )=Gen(R B,i+1 ), then delete K A,i ,K B,i ,P A,i ,R A,i ,P B,i ,SK A,i ,SK B,i ,R B,i And store K A,i+1 ,K B,i+1 ,P A,i+1 ,R A,i+1 ,P B,i+1 ,SK A,i+1 ,SK B,i+1 ,R B,i+1 Key update completed.
[0066] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A vehicle network authentication method based on PUF and fuzzy extractor, characterized in that: The method includes constructing an authentication and key exchange protocol based on PUF and fuzzy extractor, wherein the construction of the protocol involves at least three components: a vehicle network device VE, a roadside unit RSU, and a trusted center TA; in The trusted center TA is a multi-TA structure, with a master TA responsible for device registration and multiple sub-TAs responsible for assisting communication nodes in completing the authentication process; The general TA manages all sub-TAs, and each sub-TA is responsible for multiple RSUs within its authority, and RSU is fixed, VE is fluid; VE can communicate with any RSU, and RSU can only access sub-TAs in other areas under specific conditions; Specific conditions include: the sub-TA responsible for the area where the RSU is located encounters a single point failure and cannot normally access the sub-TA to assist in completing the authentication process; The protocol is divided into four phases: initialization phase, registration phase, authentication and key exchange phase, and key update phase; The initialization phase includes: the master TA randomly selects a large prime number q; the master TA randomly selects an additive group with an order of q and a generator of P; the sub-TA obtains all communication node registration data stored in the master TA from a secure channel; and The registration phase includes registration of VE and registration of RSU; the authentication and key exchange phase includes communication authentication between VE and RSU, and communication authentication between VE and VE; the key update phase includes communication authentication between VE and RSU, and communication authentication between VE and VE.
2. The vehicle network authentication method based on PUF and fuzzy extractor according to claim 1 is characterized in that: The VE registration includes: VE sends its identity information ID to the general TA through a secure channel; when the general TA receives the VE registration request, it generates a random number SK as the first key of the VE, and then calculates After receiving C from the master TA, the VE calculates R = PUF(C). The VE then stores SK and sends R to the master TA via a secure channel. After receiving R, the master TA calculates Gen(R) = (K, P) and stores ID, K, P, SK, and R in the database. The RSU registration includes: RSU sends its identity information ID to the general TA through a secure channel; when the general TA receives the RSU registration request, it selects a random number As the private key of RSU, calculate P RSU =s RSU ·P obtains the public key of RSU, and then RSU ,P RSU ) is sent to RSU through the safety channel; received from the total TA (s RSU ,P RSU ), RSU calculates Key=PUF(s RSU ) and then (s RSU ,P RSU ) is stored in the database, and then the Key is sent to the general TA; after the general TA receives the message from the RSU, the ID RSU ,Key,P RSU Stored in the database.
3. The vehicle network authentication method based on PUF and fuzzy extractor according to claim 2 is characterized in that: The specific implementation of the authentication and key exchange phase between VE and RSU includes the following steps: Step 1: VE calculates PID A,i =ID A ||SK A,i ||T1 and generate a timestamp T1, then set the PID A,i and T1 to RSU; Step 2: When RSU receives the message from VE, it first checks |T now -T1|<ΔT is established; if established, RSU generates a timestamp T2 and calculates m=hash(P RSU ||T2), then PID A,i , ID RSU , T1, T2, m are sent to the sub-TA; Step 3: When the sub-TA receives the message from the RSU, it first checks the freshness of the message; after successful verification, the sub-TA looks up the ID RSU Does it exist in the database? If so, calculate and verify the message m to authenticate the legitimacy of the RSU. After authenticating the legitimacy of the RSU, calculate and check the PID for each TA. A,i If it exists, calculate Then generate timestamp T3, calculate Finally, P A,i ,C A,i ,m1,T3 sent to RSU; Step 4: When the RSU receives the message from the TA, it first checks |T now -T3|<ΔT is established; if established, RSU generates a timestamp T4 and then A,i , P A,i , T3, T4, m1 sent to VE; Step 5: When VE receives the message from RSU, it first checks the freshness of the message. After successful verification, the vehicle uses its own PUF to calculate the response, and then uses the fuzzy extractor regeneration function to calculate K A,i =Rep(R A,i ,P A,i ) to get K A,i ,calculate Verify m1; if the verification is successful, VE generates a timestamp T5, and then calculates R A,i+1 =PUF(C A,i+1 ), then, using the data obtained from the above process, VE is calculated Then, m2, m3, and T5 are sent to the RSU; Step 6: When RSU receives the message from VE, it first checks |T now -T5|<ΔT; if so, the RSU generates a timestamp T6 and then sends m2, m3, T5, and T6 to the sub-TA; Step 7: When the sub-TA receives the message from the RSU, it first checks the freshness of the message; after successful verification, the sub-TA calculates Reusing hash(K A,i ) Decrypt m3 to get R A,i+1 , then calculate Verify m2; if the verification is successful, use the decrypted R A,i+1 and fuzzy extractor generation function calculation (K A,i+1 ,P A,i+1 )=Gen(R A,i+1 ); Then the TA uses the corresponding RSU to store the P in the memory RSU right Encrypt Then generate timestamp T7 and send S,T7 to RSU; Step 8: When the RSU receives the message from the TA, it first checks |T now -T7|<ΔT is established; if established, RSU uses P RSU Decrypt S to get Then calculate Key = PUF(s RSU ), and then use the calculated Key to perform an XOR operation to obtain the session key K for this round A,i .
4. The vehicle network authentication method based on PUF and fuzzy extractor according to claim 3 is characterized in that: The specific implementation of the authentication and key exchange phase between VEs includes the following steps: Step 1: VE A Calculating PID A,i =ID A ||SK A,i ||T1 and generate a timestamp T1, then set the PID A,i , the VE with which you want to communicate B PID sent out B,i and timestamp T B , and T1 sends to RSU; Step 2: When RSU receives VE A After receiving the message, first check |T now -T1|<ΔT is established; if established, RSU generates a timestamp T2 and calculates m=hash(P RSU ||T2), then PID A,i ,PID B,i ,ID RSU ,m,T B ,T1,T2 are sent to the sub-TA; Step 3: When the TA receives the message from the RSU, it first calculates the message based on the data stored in the database and the T B Check if the PID can be calculated B,i , thereby checking VE B Validity of identity; if verification fails, the TA rejects the authentication request, otherwise, steps 3 to 7 of the authentication and key exchange phase between VE and RSU are executed for VE A Verify the legitimacy of VE A After authentication, the TA generates a timestamp T3 and calculates Then, C B,i ,P B,i ,m1,m2,T3 are sent to RSU; Step 4: When the RSU receives the message from the TA, it first checks |T now -T3|<ΔT is established; if established, RSU generates a timestamp T4 and then B,i ,P B,i ,m1,m2,T3,T4 sent to VE A ; Step 5: When VE A After receiving the message from RSU, the VE first checks the freshness of the message. After successful verification, the VE A Generate a timestamp T5, and then use the K obtained in the previous step to A,i After hashing, decrypting m2 yields and Next, we use the R obtained in the previous step A,i Perform XOR operation to get K B,i , then calculate Verify m1; after verification, VE A calculate Then, C B,i ,P B,i ,m3,m4,T5 sent to VE B ; Step 6: When VE B Receive VE A After receiving the message, first check the freshness of the message; after successful verification, VE B Calculate R using PUF and fuzzy extractor regeneration function B,i =PUF(C B,i ) and K B,i =Rep(R B,i ,P B,i ), then calculate hash(K B,i ) Decrypt m4 to get Next, VE B Use the obtained R B,i Perform XOR operation to get K A,i ; Then, calculate To verify m3; after verification, VE B calculate Get this round and VE A The session key S.
5. The vehicle network authentication method based on PUF and fuzzy extractor according to claim 3 is characterized in that: The update phase after authentication between VE and RSU is completed includes the following steps: Step 1: VE and RSU authentication and key exchange After step 7 is completed, the TA deletes K A,i ,P A,i ,SK A,i And store K A,i+1 ,P A,i+1 ,SK A,i+1 Complete the update; Step 2: VE and RSU authentication and key exchange After step 8 is completed, VE deletes all parameters stored in the authentication process and stores SK A,i+1 Update completed.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, the vehicle network authentication method based on PUF and fuzzy extractor as described in any one of claims 1 to 5 is implemented.
7. A hardware device for Internet of Vehicles authentication, comprising a data memory, a processor, and a computer program stored in the data memory and executable on the processor, characterized in that: When the processor executes the program, the vehicle network authentication method based on PUF and fuzzy extractor is implemented as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Lightweight two-factor Internet of Vehicles bidirectional anonymous authentication system and method based on BS-PUF
CN114390474A
Authentication method of national secret certificate chain group based on pseudonym in distributed scene
CN116074055A
Authentication key negotiation method based on physical security and suitable for Internet of Vehicles environment
CN116707788A