A secure communication method based on train identity

Through a secure communication method based on train identity, public parameters and private keys are generated by a key generation center, which realizes identity authentication and data encryption between the train and the trackside infrastructure, solves the problems of data security and efficiency in the train communication system, ensures the authenticity, integrity and confidentiality of data transmission, prevents forgery and tampering, and improves the security and efficiency of communication.

CN118631459BActive Publication Date: 2025-09-30BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410890531.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-04
Publication Date
2025-09-30
Estimated Expiration
2044-07-04

AI Technical Summary

Technical Problem

Existing technologies have data security and efficiency issues in train communication systems. Malicious participants can forge or tamper with information without the key generation center being able to detect, causing traffic chaos.

Method used

A secure communication method based on train identity is adopted. Public parameters and private keys are generated by the key generation center. The train and the trackside infrastructure perform identity authentication and data encryption to ensure the authenticity and confidentiality of data transmission and reduce the overhead in the encryption and decryption stages.

Benefits of technology

It achieves the authenticity, integrity, confidentiality, unforgeability and conditional anonymity of data, prevents external attackers from tampering with data, reduces the complexity of encryption and decryption, and improves the security and efficiency of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118631459B_ABST
    Figure CN118631459B_ABST
Patent Text Reader

Abstract

The present invention discloses a secure communication method based on train identity, comprising: a key generation center generating public parameters based on security parameters; a train receiving the public parameters and ε1 and ε2, and generating a train pseudo-identity and a train private key based on t, ε1, ε2, the public parameters, and the train's true identity; the key generation center processing the legitimate train pseudo-identity, public parameters, and master key to obtain a train transmission key; processing the true identity, public parameters, and master key of the infrastructure to obtain a facility transmission key; offline processing of d, k, the public parameters, and the train transmission key to obtain offline stored partial ciphertext; the legitimate train receiving the offline stored partial ciphertext online and encrypting the information based on the train pseudo-identity, the offline stored partial ciphertext, the true identity of the infrastructure, and the public parameters to obtain ciphertext; and the trackside infrastructure decrypting the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain plaintext. The present invention enables more secure and efficient transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of digital information transmission, and in particular to a secure communication method based on train identity. Background Art

[0002] In train communication systems, trains need to communicate with trackside infrastructure, control systems, and other trains to ensure safe travel. However, due to the open nature of wireless channels, train operations generate a large amount of sensitive data, including train status information, passenger information, and dispatch instructions. This data must be strictly protected to prevent illegal access or tampering. Existing technologies use absolute anonymity to prevent the leakage of user sensitive information, but malicious actors can still deliberately spread false information, and the key generation center cannot detect the source of the false information, causing traffic disruption. Furthermore, existing solutions all rely on online network computing, which consumes a large amount of communication resources. Consequently, these solutions present security, efficiency, and practicality issues.

[0003] Therefore, there is an urgent need for a communication method that can not only protect the train's sensitive data from being forged or tampered with by attackers, but also achieve efficient and practical data transmission under the condition of limited train communication equipment resources. Summary of the Invention

[0004] The present invention is proposed based on the above-mentioned requirements of the prior art. The technical problem to be solved by the present invention is to provide a secure communication method based on train identity to achieve safer and more efficient data transmission.

[0005] In order to solve the above problems, the present invention is implemented by adopting the following technical solutions:

[0006] Provided is a secure communication method based on train identity, the method comprising: a key generation center generating a public parameter based on a security parameter, comprising: generating a bilinear group based on the security parameter, the bilinear group comprising a bilinear map e, a prime number q, a multiplicative cyclic group G of order q, and G T , and the generating element g of G; randomly select multiple hash functions based on the bilinear group, including one-way hash functions h1 and h2, and non-one-way hash functions H0, H1, H2, H3, H4, H5, H6 and H7; randomly select the set Z q * Elements ε1, ε2 and α on Z q * is a set of integers less than q and coprime to q, select elements D1 and D2 in the set G, and obtain the master key based on element α; based on the formula ω=g α Get parameters and ω; based on bilinear groups, H0, H1, H2, H3, H4, H5, H6, H7, h1, h2, and ω to obtain public parameters; the train receives the public parameters and elements ε1 and ε2 from the key generation center, and randomly selects the set Z q * Element t within; Based on element t, element ε1, element ε2, public parameters and the real identity of the train, generate a train pseudo identity and a train private key, wherein the train pseudo identity is composed of a first pseudo identity of the train and a second pseudo identity of the train, and the train private key is composed of a first private key of the train and a second private key of the train, including: obtaining the first pseudo identity PID of the train based on element t and parameter g i,1 ; Based on the train's real identity RID i and with parameters The hash value of the hash function H6 with element t as input Determine the train's second pseudo identity PID i,2 ; Based on the first pseudo identity PID of the train i,1 and element ε1 determine the first private key Prk of the train i,1 ; Based on element ε2, parameter D1, parameter D2, and the first pseudo identity PID of the train i,1 and train the second pseudo identity PID i,2 The hash value h2(PID i,1 ||PID i,2 ), using the train's first pseudo identity PID i,1 The hash value h1(PID i,1 ), determine the train's second private key Prk i,2 The key generation center processes the legitimate train pseudo-identity, public parameters and master key to obtain the train transmission key; the real identity, public parameters and master key of the trackside infrastructure are processed to obtain the facility transmission key; the set Z is randomly selected q * elements d and k in the trackside infrastructure; offline processing of element d, element k, public parameters and train transmission key obtains partial ciphertext stored offline; the legitimate train receives partial ciphertext stored offline online, and encrypts the information based on the train pseudo-identity, partial ciphertext stored offline, the real identity of the trackside infrastructure and public parameters to obtain ciphertext, and sends the ciphertext to the trackside infrastructure, where the information is the information sent by the legitimate train to the trackside infrastructure; the trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity and the facility transmission key to obtain plaintext.

[0007] Optionally, the method further includes determining whether the train is legal, including: the train sends a registration request to the key generation center, and signs the registration request based on the train private key; the key generation center receives a tuple consisting of a train pseudo identity, a registration request, and a signature from the train, and determines whether the first condition is met based on the tuple, public parameters, elements D1 and D2. If so, the train is legal; when the train identity is illegal, the key generation center checks the train's second pseudo identity PID based on the train's second pseudo identity PID. i,2 , using the train's first pseudo identity PID i,1 The hash value of the hash function H6 with element ε1 as input Get the true identity of the train.

[0008] Optionally, the registration request is signed based on the train private key, including: based on the train first private key Prk i,1 、Train second private key Prk i,2 and register request r i The hash value h1(r i ), determine the signature τ i , whose expression is Determining whether the first condition is met includes: when the first output value is equal to the product of the second output value and the third output value, the first condition is met, and the first output value is the product of the signature τ i The output value e(τ i ,g), the second output value is the first pseudo identity PID of the train i,1 , element D2, hash value h1 (PID i,1 ) and parameters The output value of the bilinear pairing function with the input, the third output value is the element D1, the hash value h2 (PID i,1 ||PID i,2 )、Hash value h1(r i ) and parameters The output value of the bilinear pairing function is expressed as

[0009] Optionally, the key generation center processes the legal train pseudo identity, public parameters and master key to obtain the train transmission key, including: the key generation center generates the train transmission key based on the parameter g, the master key α, and the train pseudo identity PID i The hash value H7 (PID i ), determine the train transmission key Its expression is

[0010] Optionally, the real identity, public parameters and master key of the trackside infrastructure are processed to obtain the facility transmission key, including: the facility transmission key includes a first part key and a second part key; based on the real identity RID of the trackside infrastructure j The hash value H0(RID j ) and the master key α, determine the first part of the key Its expression is Based on the parameter g, the real identity RID of the trackside infrastructure j The hash value H2(RID j ) and the master key α, determine the second part of the key Its expression is Based on the first part of the key and the second part of the key Get the facility transmission key sk j .

[0011] Optionally, offline processing of element d, element k, public parameters and train transmission key obtains partial ciphertext stored offline, including: the public parameters also include parameter v, the parameter v is obtained based on the formula v=e(g,g); based on parameter v and parameter d, parameter X is determined, and its expression is X=v d Based on the parameters ω, g, d and k, the parameter C1 is determined, and its expression is C1 = (ωg k ) d ;Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

[0012] Optionally, the legitimate train encrypts the information based on the train pseudo-identity, the offline stored partial ciphertext, the real identity of the trackside infrastructure and the public parameters to obtain the ciphertext, and sends the ciphertext to the trackside infrastructure. The information is the information sent by the legitimate train to the trackside infrastructure, including: based on the parameter d, the hash value H2 (RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq, mod means remainder; based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, and its expression is Based on the hash value of the hash function H4 with the information m, parameter X, parameter C1, parameter C2, parameter C3 and parameter C4 as input, the parameter y is determined, and its expression is y=H4(m,X,C1,C2,C3,C4); based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID i Input into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i ) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq; Based on parameter g, parameter γ, master key α and hash value H7(PID i ), determine the parameter C6, its expression is Based on parameters k, d, y and q, parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq; determine the ciphertext σ=(C1,C2,C3,C4,C5,C6,C7).

[0013] Optionally, the trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain the plaintext, including: determining the parameter R based on the parameter C1, the parameter g, and the parameter C4, whose expression is Based on parameters C2 and C7, determine parameter F, which is expressed as Based on the parameter R and the second part of the key Determine the parameter X', whose expression is The hash value H1(PID i ) and the first part of the key Input into the bilinear pairing function to obtain the third data; the product of the third data and the parameter C3 is input into the hash function H5 to obtain the parameter γ′, which is expressed as Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as Based on the hash value of the hash function H4 with the parameters m′, X′, C1, C2, C3 and C4 as inputs, the parameter y′ is determined, and its expression is y′=H4(m, X′, C1, C2, C3, C4); the judgment equation X=e(F, C6 1 / γ′ )v -y′Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m'=m, that is, the decryption obtains the correct information.

[0014] Optionally, the offline processing of element d, element k, public parameters and train transmission key obtains partial ciphertext stored offline, including: the bilinear group also includes a multiplicative cyclic group G1 of order q and a generating element p of G1; the master key also includes an element β, and the element β is randomly selected from the set Z q * The public parameters also include parameters ω′ and v′, the parameter ω′ is obtained based on the element p and the master key β, and its expression is ω′=p β The parameter v' is obtained based on the parameter ω and the element p, and its expression is v'=e(ω,p); Based on the parameter v' and the parameter d, the parameter X is determined, and its expression is X=(v') d Based on the parameter ω′, element p, parameter d and parameter k, the parameter C1 is determined, and its expression is C1=(ω′p k ) d ;Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

[0015] Optionally, the legitimate train encrypts the information sent by the legitimate train to the trackside infrastructure based on the train pseudo-identity, the offline stored partial ciphertext, the real identity of the trackside infrastructure and the public parameters to obtain the ciphertext, including: based on the parameter d, the hash value H2 (RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq; Based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, which is expressed as Based on the hash value of the hash function H4 with the information m, parameter X, parameter C1, parameter C2, parameter C3 and parameter C4 as input, the parameter y is determined, and its expression is y=H4(m,X,C1,C2,C3,C4); based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID i Input into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq; Based on element p, parameter γ, master key β and hash value H7(PID i ), determine the parameter C6, its expression is Based on parameters k, d, y and q, parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq; determine the ciphertext σ=(C1,C2,C3,C4,C5,C6,C7).

[0016] Optionally, the trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain the plaintext, including: determining the parameter R based on the parameter C1, the element p, and the parameter C4, whose expression is Based on parameters C2 and C7, determine parameter F, which is expressed as Based on the parameter R and the second part of the key Determine the parameter X', whose expression is The hash value H1(PID i ) and the first part of the key Input into the bilinear pairing function to obtain the third data; the product of the third data and the parameter C3 is input into the hash function H5 to obtain the parameter γ′, which is expressed as Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as Based on the hash value of the hash function H4 with the parameters m′, X′, C1, C2, C3 and C4 as inputs, the parameter y′ is determined, and its expression is y′=H4(m, X′, C1, C2, C3, C4); the judgment equation X=e(F, C6 1 / γ′ )(v') -y′ Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m'=m, that is, the decryption obtains the correct information.

[0017] Compared to existing technologies, this paper proposes a secure communication method based on train identity. This method ensures data authenticity and integrity: trains and trackside infrastructure can mutually authenticate their identities, preventing external attackers or unregistered participants from sending false, tampered, or forged data. If sensor data is detected to have been tampered with or if the sensor train signature verification fails, the trackside infrastructure discards the data. Data confidentiality is ensured: only trackside infrastructure authorized by the key generation center can verify the correctness of the signed sensor data. No other participant can obtain information from the encrypted data. Conditional anonymity and traceability are ensured: the identity of the trains in the system must be kept confidential. Specifically, no one other than the key generation center and the train itself can identify the true identity of the data source. Unforgeability is ensured: each train can only generate a valid signature for its data transmission, and other trains cannot impersonate its signature through trackside infrastructure authentication. Practicality and low overhead are achieved: the time-consuming pairing step in the encryption and decryption phases is reduced. Strong security is achieved, guaranteeing confidentiality, unforgeability, and authentication. A detailed security analysis demonstrates that this scheme can resist both the indistinguishability of chosen-ciphertext attacks and the existential unforgeability of adaptive chosen-message attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of this specification. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0019] Figure 1 This is a flow chart of a secure communication method based on train identity provided by this embodiment;

[0020] Figure 2 This is a data transmission diagram of a secure communication method based on train identity provided in this embodiment. DETAILED DESCRIPTION

[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0022] To facilitate understanding of the embodiments of the present invention, the following will be further explained with reference to specific embodiments in conjunction with the accompanying drawings. The embodiments do not constitute a limitation on the scope of protection of the present invention.

[0023] Example 1

[0024] In train communications, the entities involved include the train control center, key generation center, trains, and trackside infrastructure. The key generation center is considered a fully trusted entity, providing participant registration, key generation, and management services to other entities. The train control center typically sends data requests to trains and receives processed data from trackside infrastructure, which is used by units or management departments seeking real-time train data. Trackside infrastructure, deployed on the tracks, possesses superior computing power and storage capacity, helping trains reduce computational overhead.

[0025] The train control center, trains, and trackside infrastructure are considered semi-honest entities. On the one hand, these entities honestly follow pre-designed protocols to transmit and process sensory data and do not tamper with the data. On the other hand, they are curious about the privacy of others and attempt to leak sensitive information in various ways. Furthermore, some malicious actors attempt to disrupt the normal operation of the data transmission process, often engaging in malicious actions to maximize their own interests. For example, they may impersonate other trains or forge legitimate identities to inject false information into the network. They may tamper with others' data and collude with other trains in the system to deliberately send false information. Malicious actors may also attack the trackside infrastructure, adding, deleting, and modifying the information stored there. These actions may distort the true data, reduce trains' willingness to transmit data, and seriously affect the final outcome of the data transmission.

[0026] Based on the above, the existing technology has the following problems that need to be solved urgently: how to ensure the integrity, authenticity and confidentiality of train data at the same time; how to effectively regulate the contradiction between the demand for real-time data and the priority communication resources of the train. In order to solve the above problems, this embodiment provides a secure communication method based on train identity to ensure that the identity of participants (including trains and trackside infrastructure) is not forged, prohibit malicious participants from tampering with data uploaded by honest participants, ensure that sensitive information of the train will not be accessed by other entities in the system, and prevent collusion between malicious participants. The process of the method is as follows Figure 1 Shown, including:

[0027] The S1 key generation center generates public parameters based on security parameters.

[0028] Generate a bilinear group based on the security parameter, the bilinear group includes a bilinear map e, a prime number q, a multiplicative cyclic group G of order q and G T , and the generating element g of G, where the mapping e:G×G→G T ; Randomly select multiple hash functions based on the bilinear group, including H0:{0,1} *→G, H1:G×{0,1} * →G, H2:{0,1} * →Z q * 、H3:G T →{0,1} * 、H4: H5:G T →Z q * 、H6:G→{0,1} * 、H7:G×{0,1} * →Z q * , one-way hash functions h1 and h2; randomly select set Z q * Elements ε1, ε2 and α on Z q * is a set of integers less than q and relatively prime to q, select elements D1 and D2 in the set G0, and set α as the master key; based on the formula ω=g α Get parameters and ω; based on bilinear groups, H0, H1, H2, H3, H4, H5, H6, H7, h1, h2, and ω to obtain the common parameters.

[0029] The common parameters in this embodiment also include parameter v, which is obtained based on the formula v=e(g,g); the common parameters in this embodiment are

[0030] The key generation center is considered a fully trusted third-party organization and registers all devices interested in joining the system implementing the method of this embodiment, such as trains and trackside infrastructure. Once registered, the key generation center generates public parameters and sends them to the trains and trackside infrastructure. It also generates data transmission keys and transmits them to the trains and trackside infrastructure via a secure channel.

[0031] The S2 train receives the public parameters and elements ε1 and ε2 from the key generation center and randomly selects the set Z q * Element t within; based on element t, element ε1, element ε2, public parameters and the train's real identity, generate the train's pseudo identity and train's private key.

[0032] Each successfully registered train is equipped with communication equipment that can interact with the trackside infrastructure. The train encrypts and signs the transmitted data in real time and transmits the ciphertext and signature to the trackside infrastructure using the communication equipment.

[0033] The train's tamper-proof device (TPD) generates a train pseudo-identity. After receiving the elements ε1 and ε2 securely uploaded by the key generation center, the train TPD randomly selects an element t and calculates the train pseudo-identity PID. i and the train private key Prk i The train pseudo identity is the train first pseudo identity PID i,1 and train the second pseudo identity PID i,2 Composition, the train private key Prk i By the train's first private key Prk i,1 and the train's second private key Prk i,2 The process of generating a train pseudo-identity and a train private key includes:

[0034] Get the first pseudo identity PID of the train based on element t and parameter g i,1 , whose expression is PID i,1 =g t ; Based on the train's real identity RID i and with parameters The hash value of the hash function H6 with element t as input Determine the train's second pseudo identity PID i,2 , whose expression is Train's first pseudo-identity PID i,1 and element ε1 determine the first private key Prk of the train i,1 , whose expression is Based on element ε2, parameter D1, parameter D2, and the first pseudo identity PID of the train i,1 and train the second pseudo identity PID i,2 The hash value h2(PID i,1 ||PID i,2 ), using the train's first pseudo identity PID i,1 The hash value h1(PID i,1 ), determine the train's second private key Prk i,2 , whose expression is

[0035] The S3 key generation center processes the legal train pseudo-identity, public parameters and master key to obtain the train transmission key.

[0036] In this embodiment, when a train wants to upload sensory data, it must send a registration request to the key generation center. Only legitimate trains authenticated by the key generation center can obtain the data transmission key. Determining whether a train is legitimate involves:

[0037] The train sends a registration request to the key generation center and signs the registration request based on the train private key, including: i,1 、Train second private key Prk i,2 and register request r i The hash value h1(r i ), determine the signature τ i ;

[0038] The key generation center receives a tuple consisting of a train pseudo-identity, a registration request, and a signature from the train, and determines whether the first condition is met based on the tuple, public parameters, elements D1 and D2. If so, the train is legal, including: determining whether the first condition is met includes: when the first output value is equal to the product of the second output value and the third output value, the first condition is met, and the first output value is the signature τ i The output value e(τ i ,g), the second output value is the first pseudo identity PID of the train i,1 , element D2, hash value h1 (PID i,1 ) and parameters The output value of the bilinear pairing function with the input, the third output value is the element D1, the hash value h2 (PID i,1 ||PID i,2 )、Hash value h1(r i ) and parameters The output value of the bilinear pairing function is expressed as

[0039] After verifying the train identity, the key generation center generates a train transmission key for each legitimate train The generation process of the train transmission key is as follows:

[0040] The key generation center is based on the parameter g, the master key α, and the train pseudo identity PID i The hash value H7 (PID i ), determine the train transmission key Its expression is

[0041] Furthermore, when the train identity is illegal, the key generation center generates a second pseudo identity PID based on the train i,2 , using the train's first pseudo identity PID i,1 The hash value of the hash function H6 with element ε1 as input Get the true identity of the train, its expression is:

[0042] In this embodiment, the key generation center can track the true identity of illegal participants and resist the malicious behavior of participants without exposing the privacy of other honest participants.

[0043] The S4 key generation center processes the real identity, public parameters and master key of the trackside infrastructure to obtain the facility transmission key.

[0044] In this embodiment, when the trackside infrastructure receives data uploaded by the train, it immediately verifies the authenticity of the data and the validity of the signature. If both are correct, it proceeds to calculate the truth value of the data. Otherwise, both the data and the signature are discarded.

[0045] The key generation center uses the real identity of the trackside infrastructure to generate a facility transmission key for it. The facility transmission key includes a first key and a second key. The specific process of generating the facility transmission key includes: based on the real identity RID of the trackside infrastructure j The hash value H0(RID j ) and the master key α, determine the first part of the key Its expression is Based on the parameter g, the real identity RID of the trackside infrastructure j The hash value H2(RID j ) and the master key α, determine the second part of the key Its expression is Based on the first part of the key and the second part of the key Get the facility transmission key sk j .

[0046] S5 randomly selects set Z q * Elements d and k in the ciphertext are processed offline to obtain the partial ciphertext stored offline.

[0047] In this embodiment,

[0048] The key generation center randomly updates the elements d and k in each task, in which the sender encrypts and sends information to the receiver and the receiver receives the encrypted information and decrypts it as a task.

[0049] In this step, the specific process includes: based on the parameters v and d, determine the parameter X, which is expressed as X = v d Based on the parameters ω, g, d and k, the parameter C1 is determined, and its expression is C1 = (ωg k ) d ;Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

[0050] The S6 legitimate train receives part of the ciphertext stored offline online, encrypts the information based on the train's pseudo-identity, part of the ciphertext stored offline, the real identity of the trackside infrastructure and public parameters to obtain the ciphertext, and sends the ciphertext to the trackside infrastructure.

[0051] Messages are information sent by legitimate trains to the trackside infrastructure.

[0052] The legitimate train uses the real identity of the trackside infrastructure and the pseudo-identity of the sender to signcrypt the information to be sent. The specific process includes:

[0053] Based on parameter d, hash value H2(RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq, mod means remainder.

[0054] Based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, which is expressed as

[0055] Based on the hash value of the hash function H4 with information m, parameter X, parameter C1, parameter C2, parameter C3 and parameter C4 as input, parameter y is determined, which is expressed as y=H4(m,X,C1,C2,C3,C4).

[0056] Based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID i Input into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i ) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq.

[0057] Based on parameter g, parameter γ, master key α and hash value H7 (PID i ), determine the parameter C6, its expression is

[0058] Based on the parameters k, d, y and q, the parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq.

[0059] Determine the ciphertext σ = (C1, C2, C3, C4, C5, C6, C7) and send it to the trackside infrastructure.

[0060] In this embodiment, ciphertext generation includes an online phase and an offline phase. Most complex data calculations, such as exponential operations, are completed in the offline phase, while some lightweight operations are performed in the online phase, greatly reducing system overhead.

[0061] The S7 wayside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity and the facility transmission key to obtain the plaintext.

[0062] The wayside infrastructure uses the train transmission key to verify the validity of the perceived train signature and the integrity of the data, specifically:

[0063] Based on parameters C1, g, and C4, the parameter R is determined, and its expression is:

[0064] Based on parameters C2 and C7, determine parameter F, which is expressed as

[0065] Based on the parameter R and the second part of the key Determine the parameter X', whose expression is

[0066] The hash value H1(PID i ) and the first part of the key Input into the bilinear pairing function to obtain the third data; the product of the third data and the parameter C3 is input into the hash function H5 to obtain the parameter γ′, which is expressed as

[0067] Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as

[0068] Based on the hash value of the hash function H4 with parameters m′, X′, C1, C2, C3 and C4 as inputs, parameter y′ is determined, which is expressed as y′=H4(m, X′, C1, C2, C3, C4).

[0069] Determine the equation X=e(F,C6 1 / γ′ )v -y′Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m′=m, that is, the correct information is obtained by decryption, and it is determined that the train's signature on the information m is valid.

[0070] Ciphertext legitimacy means that the trackside infrastructure verifies that the train has signed the information. If there is no signature, it indicates that the ciphertext was transmitted by an unregistered or illegal user, and the trackside infrastructure will discard or not process such information. After confirming the legitimacy of the ciphertext, the ciphertext must also be verified for accuracy. This is because ciphertext can be corrupted by malicious users during transmission. This is achieved by determining whether the equation X = X' holds.

[0071] The derivation process of the equation is as follows:

[0072] If the ciphertext is valid, then:

[0073]

[0074] The receiver (i.e., the trackside infrastructure) uses its key to obtain the correct parameter X. After obtaining the correct X, the correct m and y can be calculated and pass the verification check.

[0075]

[0076] Compared to existing technologies, this embodiment proposes a secure communication method based on train identity. This method ensures data authenticity and integrity: trains and trackside infrastructure can mutually authenticate their identities, preventing external attackers or unregistered participants from sending false, tampered, or forged data. If sensor data is detected to have been tampered with or if the sensor train signature verification fails, the trackside infrastructure discards the data. Data confidentiality is ensured: only trackside infrastructure authorized by the key generation center can verify the correctness of the signed sensor data. No other participant can obtain information from the encrypted data. Conditional anonymity and traceability are ensured: the identity of the trains in the system must be kept confidential. Specifically, no one other than the key generation center and the train itself can identify the true identity of the data source. Unforgeability is ensured: each train can only generate a valid signature for its data transmission, and other trains cannot impersonate its signature through trackside infrastructure authentication. Practicality and low overhead are achieved: the time-consuming pairing step in the encryption and decryption phases is reduced. Strong security is achieved, guaranteeing confidentiality, unforgeability, and authentication. A detailed security analysis demonstrates that this scheme can resist both the indistinguishability of chosen-ciphertext attacks and the existential unforgeability of adaptive chosen-message attacks.

[0077] Example 2

[0078] This embodiment provides a secure communication method based on train identity.

[0079] The parts that are the same as those in Example 1 will not be described in detail here.

[0080] Corresponding to S1 in the embodiment, the difference of this embodiment is that the bilinear group further includes a multiplicative cyclic group G1 of order q and a generator element p of G1; the master key also includes an element β, which is randomly selected from the set Z q * The public parameters also include parameters ω′ and v′, wherein the parameter ω′ is obtained based on the element p and the master key β, and its expression is ω′=p β The parameter v' is obtained based on the parameter ω and the element p, and its expression is v'=e(ω,p), that is, the common parameters of this embodiment are

[0081] Corresponding to S5 in Example 1, the difference of this embodiment is that the offline stored partial ciphertext is obtained by processing element d, element k, public parameters and train transmission key. Specifically, it includes: based on parameter v' and parameter d, determining parameter X, whose expression is X = (v') d Based on the parameter ω′, element p, parameter d and parameter k, the parameter C1 is determined, and its expression is C1=(ω′p k ) d ;Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

[0082] Corresponding to S6 in Example 1, the ciphertext obtained in this embodiment is different. The legitimate train encrypts the information based on the train pseudo-identity, the partial ciphertext stored offline, the real identity of the trackside infrastructure and the public parameters to obtain the ciphertext, including: based on the parameter d, the hash value H2 (RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq; Based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, which is expressed as Based on the hash value of the hash function H4 with the information m, parameter X, parameter C1, parameter C2, parameter C3 and parameter C4 as input, the parameter y is determined, and its expression is y=H4(m,X,C1,C2,C3,C4); based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID iInput into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i ) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq; Based on element p, parameter γ, master key β and hash value H7(PID i ), determine the parameter C6, its expression is Based on parameters k, d, y and q, parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq; determine the ciphertext σ=(C1,C2,C3,C4,C5,C6,C7).

[0083] Different from S7 in Example 1, the process of obtaining the plaintext in this embodiment is as follows: the trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain the plaintext, including: determining the parameter R based on the parameter C1, the element p, and the parameter C4, which is expressed as Based on parameters C2 and C7, determine parameter F, which is expressed as Based on the parameter R and the second part of the key Determine the parameter X', whose expression is The hash value H1(PID i ) and the first part of the key Input into the bilinear pairing function to obtain the third data; the product of the third data and the parameter C3 is input into the hash function H5 to obtain the parameter γ′, which is expressed as Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as Based on the hash value of the hash function H4 with the parameters m′, X′, C1, C2, C3 and C4 as inputs, the parameter y′ is determined, and its expression is y′=H4(m, X′, C1, C2, C3, C4); the judgment equation X=e(F, C6 1 / γ′ )v -y′ Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m'=m, that is, the decryption obtains the correct information.

[0084] The derivation process of the equation is as follows:

[0085] If the ciphertext is valid, then:

[0086]

[0087] The receiver (i.e., the trackside infrastructure) uses its key to obtain the correct parameter X. After obtaining the correct X, the correct m and y can be calculated and pass the verification check.

[0088]

[0089] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A secure communication method based on train identity, characterized in that: include: The key generation center generates a public parameter based on the security parameter, including: generating a bilinear group based on the security parameter, wherein the bilinear group includes a bilinear map e, a prime number q, a multiplication cyclic group G of order q, and G T , and the generating element g of G; randomly select multiple hash functions based on the bilinear group, including one-way hash functions h1 and h2, and non-one-way hash functions H0, H1, H2, H3, H4, H5, H6 and H7; randomly select the set Z q * Elements ε1, ε2 and α on Z q * is a set of integers less than q and relatively prime to q, select elements D1 and D2 in the set G, and obtain the master key based on element α; based on the formula ω=g α Get parameters and ω; based on bilinear groups, H0, H1, H2, H3, H4, H5, H6, H7, h1, h2, and ω to obtain common parameters; The train receives the public parameters and elements ε1 and ε2 from the key generation center and randomly selects the set Z q * Element t within; Based on element t, element ε1, element ε2, public parameters and the real identity of the train, generate a train pseudo identity and a train private key, wherein the train pseudo identity is composed of a first pseudo identity of the train and a second pseudo identity of the train, and the train private key is composed of a first private key of the train and a second private key of the train, including: obtaining the first pseudo identity PID of the train based on element t and parameter g i,1 ; Based on the train's real identity RID i and with parameters The hash value of the hash function H6 with element t as input Determine the train's second pseudo identity PID i,2 ; Based on the first pseudo identity PID of the train i,1 and element ε1 determine the first private key Prk of the train i,1 ; Based on element ε2, parameter D1, parameter D2, and the first pseudo identity PID of the train i,1 and train the second pseudo identity PID i,2 The hash value h2(PID i,1 ||PID i,2 ), using the train's first pseudo identity PID i,1 The hash value h1(PID i,1 ), determine the train's second private key Prk i,2 ; The key generation center processes the legitimate train pseudo-identity, public parameters and master key to obtain the train transmission key; processes the real identity, public parameters and master key of the trackside infrastructure to obtain the facility transmission key; randomly selects the set Z q * Elements d and k in the ciphertext; offline processing of element d, element k, public parameters and train transmission key to obtain offline stored partial ciphertext; The legitimate train receives the offline stored partial ciphertext online, encrypts the information based on the train's pseudo-identity, the offline stored partial ciphertext, the real identity of the trackside infrastructure, and public parameters to obtain the ciphertext, and sends the ciphertext to the trackside infrastructure. The ciphertext is the information sent by the legitimate train to the trackside infrastructure; The trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity and the facility transmission key to obtain the plaintext.

2. A secure communication method based on train identity according to claim 1, characterized in that: The method further includes determining whether the train is legal, including: The train sends a registration request to the key generation center, which signs the registration request based on the train's private key; The key generation center receives a tuple consisting of the train pseudo-identity, registration request, and signature from the train, and determines whether the first condition is met based on the tuple, public parameters, elements D1 and D2. If so, the train is legal; When the train identity is illegal, the key generation center uses the train's second pseudo identity PID i,2 , using the train's first pseudo identity PID i,1 The hash value of the hash function H6 with element ε1 as input Get the true identity of the train.

3. A secure communication method based on train identity according to claim 2, characterized in that: Sign the registration request based on the train's private key, including: Based on the train's first private key Prk i,1 、Train second private key Prk i,2 and register request r i The hash value h1(r i ), determine the signature τ i , whose expression is Determining whether the first condition is met includes: The first condition is met when the first output value is equal to the product of the second output value and the third output value, and the first output value is the product of the second output value and the third output value. i The output value e(τ i ,g), the second output value is the first pseudo identity PID of the train i,1 , element D2, hash value h1 (PID i,1 ) and parameters The output value of the bilinear pairing function is the input, and the third output value is the element D1, the hash value h2 (PID i,1 ||PID i,2 、Hash value h1(r i ) and parameters The output value of the bilinear pairing function is expressed as 4. A secure communication method based on train identity according to claim 1, characterized in that: The key generation center processes the legal train pseudo-identity, public parameters and master key to obtain the train transmission key, including: The key generation center is based on the parameter g, the master key α, and the train pseudo identity PID i The hash value H7 (PID i ), determine the train transmission key Its expression is The processing of the real identity, public parameters and master key of the trackside infrastructure to obtain the facility transmission key includes: The facility transmission key includes a first key portion and a second key portion; Based on the real identity RID of trackside infrastructure j The hash value H0(RID j ) and the master key α, determine the first part of the key Its expression is Based on the parameter g, the real identity RID of the trackside infrastructure j The hash value H2(RID j ) and the master key α, determine the second part of the key Its expression is Based on the first part of the key and the second part of the key Get the facility transmission key sk j .

5. A secure communication method based on train identity according to claim 4, characterized in that: Offline processing of element d, element k, public parameters and train transmission key obtains partial ciphertext stored offline, including: The common parameters also include a parameter v, which is obtained based on the formula v=e(g,g); Based on the parameters v and d, determine the parameter X, which is expressed as X = v d ; Based on the parameters ω, g, d and k, the parameter C1 is determined, and its expression is C1=(ωg k ) d ; Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

6. A train identity-based secure communication method according to claim 5, characterized in that: The legitimate train encrypts the information sent by the legitimate train to the trackside infrastructure based on the train's pseudo-identity, the offline stored partial ciphertext, the real identity of the trackside infrastructure, and public parameters to obtain the ciphertext, including: Based on parameter d, hash value H2(RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq, mod means remainder; Based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, which is expressed as Determine parameter y based on the hash value of hash function H4 with information m, parameter X, parameter C1, parameter C2, parameter C3, and parameter C4 as input, expressed as y=H4(m,X,C1,C2,C3,C4); Based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID i Input into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i ) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq; Based on parameter g, parameter γ, master key α and hash value H7 (PID i ), determine the parameter C6, its expression is Based on parameters k, d, y and q, parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq; Determine the ciphertext σ = (C1, C2, C3, C4, C5, C6, C7).

7. A train identity-based secure communication method according to claim 6, characterized in that: The trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain the plaintext, including: Based on parameters C1, g, and C4, the parameter R is determined, and its expression is: Based on parameters C2 and C7, determine parameter F, which is expressed as Based on the parameter R and the second part of the key Determine the parameter X', which is expressed as The hash value H1(PID i ) and the first part of the key Input the third data into the bilinear pairing function to obtain the third data; input the product of the third data and the parameter C3 into the hash function H5 to obtain the parameter γ′, which is expressed as Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as Determine parameter y' based on the hash value of hash function H4 with parameter m', parameter X', parameter C1, parameter C2, parameter C3, and parameter C4 as input, and the expression is y'=H4(m,X',C1,C2,C3,C4); Determine the equation X=e(F,C6 1 / γ′ )v -y′ Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m'=m, that is, the decryption obtains the correct information.

8. A train identity-based secure communication method according to claim 4, characterized in that: Offline processing of element d, element k, public parameters and train transmission key obtains partial ciphertext stored offline, including: The bilinear group also includes a multiplicative cyclic group G1 of order q and a generator element p of G1; The master key is replaced by an element β, which is randomly selected from the set Z q * Select The public parameters also include parameters ω′ and v′. The parameter ω′ is obtained based on the element p and the master key β. Its expression is ω′=p β The parameter v' is obtained based on the parameter ω and the element p, and its expression is v'=e(ω,p); Based on the parameters v' and d, determine the parameter X, which is expressed as X = (v') d ; Based on the parameter ω′, the element p, the parameter d and the parameter k, the parameter C1 is determined, and its expression is C1=(ω′p k ) d ; Train-based transmission key And parameter k, determine the parameter C2, its expression is Based on the parameters g and d, the parameter C3 is determined, and its expression is C3=g d ; Determine the partial ciphertext σ stored offline off =(X,d,k,C1,C2,C3).

9. A train identity-based secure communication method according to claim 8, characterized in that: The legitimate train encrypts the information sent by the legitimate train to the trackside infrastructure based on the train's pseudo-identity, the offline stored partial ciphertext, the real identity of the trackside infrastructure, and public parameters to obtain the ciphertext, including: Based on parameter d, hash value H2(RID j ), parameters k and g, determine the parameter C4, which is expressed as C4 = d × (H2 (RID j )-k)modq; Based on the information m and the hash value H3(X) of the hash function H3 with the parameter X as input, the parameter C5 is determined, which is expressed as Determine parameter y based on the hash value of hash function H4 with information m, parameter X, parameter C1, parameter C2, parameter C3, and parameter C4 as input, expressed as y=H4(m,X,C1,C2,C3,C4); Based on the hash value H0(RID j ), parameter d and parameter ω to obtain the first data; the train pseudo identity PID i Input into the hash function H1 to get the hash value H1 (PID i ); Hash value H1(PID i ) and the first data are input into a bilinear pairing function to obtain the second data; based on the hash value of the hash function H5 with the second data as input and the parameter q, the parameter γ is determined, and its expression is γ=H5(e(H1(PID i ),ω×H0(RID j ) d ))modq; Based on element p, parameter γ, master key β and hash value H7(PID i ), determine the parameter C6, its expression is Based on parameters k, d, y and q, parameter C7 is determined, and its expression is C7=k -1 ×(d+y)modq; Determine the ciphertext σ = (C1, C2, C3, C4, C5, C6, C7).

10. A train identity-based secure communication method according to claim 9, characterized in that: The trackside infrastructure decrypts the ciphertext based on the public parameters, the train pseudo-identity, and the facility transmission key to obtain the plaintext, including: Based on parameter C1, element p and parameter C4, the parameter R is determined, and its expression is Based on parameters C2 and C7, determine parameter F, which is expressed as Based on the parameter R and the second part of the key Determine the parameter X', which is expressed as The hash value H1(PID i ) and the first part of the key Input into the bilinear pairing function to obtain the third data; the product of the third data and the parameter C3 is input into the hash function H5 to obtain the parameter γ′, which is expressed as Based on the parameter C5 and the hash value H3(X′) of the hash function H3 with the parameter X′ as input, the parameter m′ is determined, which is expressed as Determine parameter y' based on the hash value of hash function H4 with parameter m', parameter X', parameter C1, parameter C2, parameter C3, and parameter C4 as input, and the expression is y'=H4(m,X',C1,C2,C3,C4); Determine the equation X=e(F,C6 1 / γ′ )v -y′ Is it true? If so, the ciphertext is legal, and judge whether the equation X=X' is true. If so, then m'=m, that is, the decryption obtains the correct information.

Citation Information

Patent Citations

  • Identity-based high-efficiency data transmission method in vehicular ad hoc network

    CN106452762A

  • Maglev train control system privacy protection authentication method based on bilinear mapping

    CN116074030A