A User Privacy Protection Method and System Based on Dilithium Certificateless Blind Signature Scheme in Vehicle Networking

Through the Dilithium certificate-free blind signature solution, the trusted center and base station generate public keys, combined with post-quantum algorithm, the problems of quantum attacks and computing overhead in the Internet of Vehicles are solved, and vehicle privacy data protection and lightweight communication are realized.

CN118764214BActive Publication Date: 2025-07-11BEIJING ELECTRONICS SCI & TECH INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410946183.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-15
Publication Date
2025-07-11
Estimated Expiration
2044-07-15

AI Technical Summary

Technical Problem

In the Internet of Vehicles, the existing certificate-free public key cryptographic authentication scheme faces the threat of quantum attacks and has large computing overhead, and the certificate management is cumbersome, making it impossible to effectively protect vehicle privacy data.

Method used

The Dilithium certificate-free blind signature scheme is adopted, and the system public and private keys are generated using a trusted center. Through the blinding factor and deblind process of base stations and vehicle users, the protection of private data is achieved, and the post-quantum algorithm is combined with the post-quantum algorithm to resist quantum attacks.

Benefits of technology

It realizes the protection of vehicle privacy data, reduces computing and storage overhead, adapts to the environment of constrained vehicle network resources, and can resist quantum attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118764214B_ABST
    Figure CN118764214B_ABST
Patent Text Reader

Abstract

The present invention discloses a user privacy protection method and system based on the Dilithium certificateless blind signature scheme in the vehicle networking. This method enables the base station in the vehicle networking to initiate a registration request for identity information to the trusted center, and the trusted center generates the first part of the private key and the corresponding tag; the base station verifies the first part of the private key; the base station calculates the second part of the private key and generates the complete public-private key pair of the base station; the base station sends a commitment message to the vehicle user, and the vehicle user initiates a signature request to the base station; the base station signs the blinded information and returns it to the vehicle user; the vehicle user unblinds the received blinded signature to obtain the true signature for the privacy data; the vehicle user uploads the privacy data and the true signature to the management agency for authentication; the management agency verifies the true signature of the vehicle user and stores the privacy data. The present invention protects various privacy data and meets the requirements of the vehicle networking for resisting quantum attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of vehicle networking and information security, and particularly to a method and system for protecting user privacy based on a Dilithium certificateless blind signature scheme in vehicle networking. Background Art

[0002] Currently, during the process of open-channel communication and data uploading in vehicle networking, the risk of leakage of perception data, vehicle location information, vehicle identity information, etc. collected by vehicles is very high, which damages the privacy of vehicle users and causes vehicle networking to be unable to guarantee data security. Blind signature is one of the most important methods to ensure the security of privacy data.

[0003] In related technologies, vehicle networking authentication schemes are divided into traditional public key infrastructures, identity-based public key cryptography, and certificateless public key cryptography. Existing blind signature schemes in vehicle networking are based on the PKI system and have problems in certificate management. In the public key infrastructure, the certificate issuing authority needs to equip each vehicle networking terminal with a public-private key pair. The access of a large number of terminals may lead to cumbersome management and resource consumption. However, due to the limited resources of vehicle networking, a lightweight scheme is required for communication. In the certificateless cryptosystem, the user's private key is composed of the user's partial private key generated by the key center and the secret value selected by the user. The cryptosystem does not require digital certificates and can solve the certificate management problem. In addition, the key generation center only has the user's partial private key, and at the same time can solve the key escrow problem, and is widely used in current vehicle networking identity authentication.

[0004] However, most current certificateless public key cryptography authentication schemes are designed based on classical number theory difficulties such as elliptic curves. However, with the rise of quantum computing, the security of certificateless schemes is greatly threatened in the face of quantum attacks. In addition, the data collection and specific calculations related to matrix operations require the use of complete data, which may lead to huge computational overhead. Summary of the Invention

[0005] The present invention aims to solve at least one of the technical problems in the related technologies to some extent.

[0006] To this end, the present invention proposes a method for protecting user privacy based on a Dilithium certificateless blind signature scheme in vehicle networking. Based on the Dilithium certificateless blind signature scheme, the certificateless cryptosystem is used to replace the PKI system, which can solve the certificate management problem and lightweight the communication protocol; at the same time, the post-quantum standard signature scheme Dilithium is used to replace the existing classical number theory difficulties such as elliptic curves, so that the scheme can resist quantum attacks; the blind signature scheme is used to protect privacy data such as perception information, vehicle location, and vehicle identity information collected by vehicles to achieve the privacy protection of vehicle users.

[0007] Another object of the present invention is to propose a user privacy protection system based on the Dilithium certificateless blind signature scheme in the vehicle networking.

[0008] To achieve the above object, on the one hand, the present invention proposes a user privacy protection method based on the Dilithium certificateless blind signature scheme in the vehicle networking, including:

[0009] Generating a system public key, a system private key, and system public parameters by a trusted center based on a post-quantum algorithm;

[0010] Initiating a registration request for identity information to the trusted center by a base station of the vehicle networking, and generating a first part of the private key and a corresponding tag by the trusted center through a post-quantum algorithm;

[0011] Verifying the first part of the private key by the base station according to the received tag;

[0012] Calculating a second part of the private key by the base station and generating a complete public-private key pair of the vehicle networking base station according to the verified first part of the private key, and broadcasting the complete public key in the vehicle networking;

[0013] Sending a commitment message to a vehicle user by the base station, and initiating a signature request to the base station by the vehicle user after obscuring the privacy data through a blinding factor;

[0014] Signing the obscured information by the base station and returning it to the vehicle user;

[0015] Unblinding the received blinded signature by the vehicle user to obtain a true signature for the privacy data;

[0016] Uploading the privacy data and the true signature to a management agency by the vehicle user to request authentication;

[0017] Verifying the true signature of the vehicle user by the management agency according to the public key broadcast by the base station and storing the privacy data.

[0018] To achieve the above object, the second aspect of the present application proposes a user privacy protection system based on the Dilithium certificateless blind signature scheme in the vehicle networking, including:

[0019] An initialization module, configured to generate system public parameters, a system public key, and a system private key by a trusted center, and publicly disclose the system public parameters and the system public key in the vehicle networking, and secretly store the system private key;

[0020] A first part of the post-quantum private key generation module, configured to generate a first part of the private key by a post-quantum algorithm after the trusted center receives a request for identity registration and generation of the first part of the private key from a base station in the vehicle networking;

[0021] The second part of the post-quantum private key generation module is used to generate the second part of the private key by using the base station;

[0022] The complete post-quantum public-private key pair generation module is used to generate a complete post-quantum public-private key pair by using the base station according to the generated first part of the private key and the generated second part of the private key, and broadcast the complete public key in the vehicle network;

[0023] The blind transformation module is used to blur the privacy data by the vehicle user through the blinding factor;

[0024] The signature module is used to sign the blinded information by the base station;

[0025] The de-blinding transformation module is used to de-blind the received blinded signature by the vehicle user to obtain the true signature for the privacy data;

[0026] The verification module is used to authenticate the identity of the message and the true signature sent by the vehicle user by the management agency.

[0027] The user privacy protection method and system based on the Dilithium certificateless blind signature scheme in the vehicle network according to the embodiment of the present invention are applicable to the characteristics of limited computing resources in the vehicle network, protect privacy data such as the sensing information, vehicle location, and vehicle identity information collected by the vehicle, and at the same time meet the requirements of the vehicle network for resisting quantum attacks.

[0028] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The above and / or additional aspects and advantages of the present invention will become apparent and easy to understand from the following description of the embodiments in conjunction with the drawings, in which:

[0030] Figure 1 is a flowchart of a user privacy protection method based on the Dilithium certificateless blind signature scheme in a vehicle network according to an embodiment of the present invention;

[0031] Figure 2 is a schematic structural diagram of a user privacy protection method based on the Dilithium certificateless blind signature scheme in a vehicle network according to an embodiment of the present invention;

[0032] Figure 3 is a structural block diagram of a user privacy protection system based on the Dilithium certificateless blind signature scheme in a vehicle network according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in combination with the embodiments.

[0034] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0035] A user privacy protection method and system based on the Dilithium certificateless blind signature scheme in the vehicle networking will be described below with reference to the drawings according to an embodiment of the present invention.

[0036] Figure 1 is a flowchart of a user privacy protection method based on the Dilithium certificateless blind signature scheme in the vehicle networking according to an embodiment of the present invention. As Figure 1 shown, the method includes:

[0037] S1, generating a system public key, a system private key, and system public parameters based on a post-quantum algorithm by a trusted center;

[0038] S2, using the base station of the vehicle networking to initiate a registration request for identity information to the trusted center, and using the trusted center to generate a first part of the private key and a corresponding tag through a post-quantum algorithm;

[0039] S3, using the base station to verify the first part of the private key according to the received tag;

[0040] S4, calculating a second part of the private key by the base station and generating a complete public-private key pair of the vehicle networking base station according to the verified first part of the private key, and broadcasting the complete public key in the vehicle networking;

[0041] S5, sending a commitment message to the vehicle user by the base station, and the vehicle user blurs the privacy data through a blinding factor and then initiates a signature request to the base station;

[0042] S6, signing the blinded information by the base station and returning it to the vehicle user;

[0043] S7, using the vehicle user to unblind the received blinded signature to obtain the true signature for the privacy data;

[0044] S8, uploading the privacy data and the true signature to the management agency by the vehicle user for authentication;

[0045] S9. The management agency verifies the real signature of the vehicle user according to the public key broadcast by the base station and stores the privacy data.

[0046] Among them, the base station BS sends a registration request to the trusted center TA; calculates the complete public and private keys; signs the blinded information to generate a blinded signature.

[0047] Among them, the vehicle user in the vehicle networking sends a signature application to the base station BS, performs blind transformation and de - blind transformation on the privacy data, and sends an authentication request to the government management agency CC.

[0048] Among them, the government management agency CC stores the authentication data in the vehicle networking system; provides data communication services for the vehicle users in the vehicle networking, and can realize data sharing and identity authentication among vehicle users.

[0049] Specifically, as Figure 2 shown, it is a system schematic diagram of the user privacy protection method based on the Dilithium certificateless blind signature scheme in the vehicle networking of the present invention.

[0050] In an embodiment of the present invention, step S1 includes that the trusted center TA selects appropriate parameters, combines with the post - quantum algorithm to generate a pair of system public key, system private key, and system public parameters, publishes the system public parameters and system public key in the vehicle networking, and secretly stores the system private key. The specific steps can be:

[0051] Step S11: The trusted center TA randomly selects two random number seeds ρ←{0,1} 256 , K←{0,1} 256 , and respectively obtains an l - order vector s1 and a k - order vector s2 by sampling on the uniform distribution, where l and k are positive integers.

[0052] Step S12: The trusted center TA generates a k×l - order matrix A = ExpandA(ρ), and calculates the k - order vector t = As1 + s2. Where ExpandA() is a hash algorithm defined by the NIST post - quantum standard signature algorithm Dilithium.

[0053] Step S13: The trusted center TA generates system public parameters params={H1,H2,H3,γ1,γ2,β}, where H1,H2,H3 are general hash functions, and γ1,γ2,β are parameters set by the system.

[0054] Step S14: The trusted center TA generates a pair of system public and private key pairs, the system public key pk =(ρ,t), the system private key sk=(ρ,K,s1,s2), and makes the public key public and sets the private key as private.

[0055] Among them, the trusted center TA is a third-party trusted institution responsible for the initialization of the vehicle networking system and generating system parameters, and providing registration services for the base station and vehicle users.

[0056] In an embodiment of the present invention, step S2 includes the vehicle networking base station BS submitting identity information to the trusted center TA for registration. After passing the verification, the trusted center generates the first part of the private key and the corresponding tag and sends them to the base station BS. The specific steps can be as follows:

[0057] Step S21: The vehicle networking base station BS submits the identity information ID s to the trusted center TA for registration;

[0058] Step S22: The trusted center TA randomly selects a random number seed ρ1←{0,1} 256 , and calculates the l-order vector ExpandMask() is a hash algorithm defined by the NIST post-quantum standard signature algorithm Dilithium;

[0059] Step S23: The trusted center TA calculates R s =Ar s , and decomposes the vector into high and low order bits (R s1 ,R s0 ):=Decompose(R s ,2γ2). The Decompose() algorithm controls the change of the high-order bits within 1 by selecting appropriate parameters;

[0060] Step S24: The trusted center TA calculates c1 = H1(t||ID s ||R s1 ) and the first part of the private key d s =c1s1+r s , and sends (d s ,c1) to the base station BS applying for registration.

[0061] In an embodiment of the present invention, step S3 includes the base station BS verifying the first part of the private key according to the tag received from the trusted center TA. The specific steps can be as follows:

[0062] Step S31: After receiving the first part of the private key d s and the hash function value c1 sent by the trusted center TA, the base station BS calculates R' A1 :=HighBits(Ad s -c1t,2γ2);

[0063] Step S32: The base station BS verifies c1 = H1(t||ID s ||R s'1) Whether it holds. If not, reject the first part of the private key and re-apply to the trusted center TA for the first part of the private key.

[0064] In an embodiment of the present invention, step S4 includes the base station BS calculating the second part of the private key and combining it with the first part of the private key to generate a complete public-private key pair for the base station BS for identity authentication and broadcasting the complete public key in the vehicle network. The specific steps can be:

[0065] Step S41: The base station BS randomly selects two random number seeds ρ2←{0,1} 256 , K1←{0,1} 256 ;

[0066] Step S42: The base station BS samples on a uniform distribution to obtain a k-order vector x s as the second part of the private key of the vehicle terminal

[0067] Step S43: The base station BS performs high and low order bit calculations on the first part of the private key, (d s1 , d s0 ):=Power2Round q (d s , γ3);

[0068] Step S44: The base station BS calculates w:=Ad s0 +x s ;

[0069] Step S45: The base station BS sets the complete public key pk s =w, and the complete private key sk s =(K1, ρ2, d s0 , x s ), and broadcasts the base station public key pk s in the vehicle network.

[0070] In an embodiment of the present invention, step S5 includes the base station BS first making a commitment to the vehicle user, and the vehicle user blurs the privacy data through a blinding factor and then sends it to the nearby base station BS to request a signature. The specific steps can be:

[0071] Step S51: The base station BS selects an l-order vector calculates Y′=Ay, and sends Y′ to the vehicle user for commitment;

[0072] Step S52: The vehicle user performs blinding processing on the privacy data, selects an l-order vector and a random number b∈S η, compute the hash value μ = CRH(ρ||M) for the message M to be sent, where CRH() is the hash algorithm defined by the NIST post-quantum standard signature algorithm Dilithium;

[0073] Step S53: The vehicle user computes the hash value c2 = H2(ID s ,PK s ,pk),

[0074] Y1 = HighBit(Y′ + Aa + c2b, 2γ2);

[0075] Step S54: The vehicle user verifies LowBit(Y′ + Aa + c2b, 2γ2). If it holds, compute the signature value e = H3(Y1, μ), and send the signature value e to the base station BS to request a signature.

[0076] In an embodiment of the present invention, step S6 includes the base station BS signing the blinded information and returning it to the vehicle user. The specific steps may be:

[0077] Step S61: The base station BS computes z′ = ed s0 +y, and performs rejection sampling on z′. The rejection sampling calculation method includes: The base station BS verifies ||z′|| ∞ ≥γ1 - β. If it holds, jump to step S52, where ||z′|| ∞ represents the infinity norm of the vector;

[0078] Step S62: The base station BS sends the signature value z′ to the vehicle user.

[0079] In an embodiment of the present invention, step S7 includes the vehicle user unblinding the received blinded signature to obtain the signature for the true privacy data. The specific steps include:

[0080] Step S71: After receiving the signature value z′ of the blinded information sent by the base station BS, the vehicle user computes z = z′ + a;

[0081] Step S72: The vehicle user computes the true signature value σ = (z, e).

[0082] In an embodiment of the present invention, step S8 includes the vehicle user uploading the privacy data and the true signature together to the government-administered agency CC for authentication. The specific steps include:

[0083] Step S81: The vehicle user sends the true signature value σ = (z, e) and the message M to the government-administered agency CC and waits for authentication.

[0084] In one embodiment of the present invention, step S9 includes that the government management agency CC verifies the real signature of the vehicle user according to the public key broadcast by the base station BS, stores the privacy data, and provides services and shares data for all vehicles according to the data. The specific steps may be as follows:

[0085] Step S91: After receiving the message M and the signature value σ = (z, e), the government management agency CC calculates the hash value μ = CRH(ρ||M) and the vehicle networking public matrix A = ExpandA(ρ);

[0086] Step S92: The government management agency CC calculates Y1′ = HighBit(Az - ew, 2γ2), and stores and processes the privacy information c2 of the vehicle user = H2(ID s , PK s , pk);

[0087] Step S93: The government management agency CC verifies e = H3(Y1', μ). If it holds, the signature of the vehicle user passes the authentication.

[0088] According to the user privacy protection method based on the Dilithium certificateless blind signature scheme in the vehicle networking of the embodiments of the present invention, the certificateless avoids the certificate authentication and management overhead in the traditional PKI authentication, lightens the communication protocol, and meets the requirements of distributed and massive terminals in the vehicle networking; at the same time, based on the post-quantum standard signature scheme Dilithium, it replaces the existing signature schemes still based on classical number theory difficult problems such as elliptic curves, solves the problem that the traditional signature authentication method in the vehicle networking cannot resist quantum attacks, and meets the requirements of the vehicle networking for resisting quantum attacks.

[0089] The beneficial effects of the present invention may be:

[0090] The blind signature is used to protect the privacy data such as the perception information, vehicle location, and vehicle identity information collected by the vehicle. In this scheme, the vehicle fuzzifies the privacy data through the blinding factor and then sends it to the nearby base station to request a signature. After the base station signs the blinded information, it returns it to the vehicle. After the vehicle obtains the blinded signature, it performs de-blinding to obtain the signature for the real privacy data and uploads it to the government-administered agency for storage together with the privacy data, and provides services and shares data for all vehicles according to the data. Through the blind signature, the base station and other data-sharing vehicles cannot obtain the privacy information of the data-uploading vehicle, and the government management agency can ensure that the data comes from the legally registered users in the vehicle networking. The user privacy protection method based on the Dilithium certificateless blind signature scheme disclosed by the present invention has great advantages in terms of computing efficiency and storage overhead, is easy to implement and deploy, and is applicable to the vehicle networking applications with limited computing resources and storage resources.

[0091] To implement the method of the above embodiments, the present invention also provides a user privacy protection system based on the Dilithium certificateless blind signature scheme in the vehicle networking, including:

[0092] An initialization module 100, configured to generate system public parameters, a system public key, and a system private key by using a trusted center, publicly disclose the system public parameters and the system public key in the vehicle networking, and secretly save the system private key;

[0093] A first part of post-quantum private key generation module 200, configured to generate a first part of the private key by using a post-quantum algorithm after the trusted center receives a request for identity registration and generation of the first part of the private key from a base station in the vehicle networking;

[0094] A second part of post-quantum private key generation module 300, configured to generate a second part of the private key by using the base station;

[0095] A complete post-quantum public-private key pair generation module 400, configured to generate a complete post-quantum public-private key pair by using the base station according to the generated first part of the private key and the generated second part of the private key, and broadcast the complete public key in the vehicle networking;

[0096] A blind transformation module 500, configured to fuzzify privacy data by a vehicle user through a blinding factor;

[0097] A signature module 600, configured to sign the blinded information by the base station;

[0098] A deblinding transformation module 700, configured to deblind the received blinded signature by the vehicle user to obtain a true signature for the privacy data;

[0099] A verification module 800, configured to authenticate the identity of the message and the true signature sent by the vehicle user by a management agency.

[0100] According to the user privacy protection system based on the Dilithium certificateless blind signature scheme in the vehicle networking of the embodiments of the present invention, the certificatelessness avoids the certificate authentication and management overhead in the traditional PKI authentication, lightens the communication protocol, and meets the requirements of the distributed and massive terminals in the vehicle networking; at the same time, based on the post-quantum standard signature scheme Dilithium, it replaces the existing signature scheme still based on classical number theory difficult problems such as elliptic curves, solves the problem that the traditional signature authentication method in the vehicle networking cannot resist quantum attacks, and meets the requirements of the vehicle networking for resisting quantum attacks.

[0101] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0102] In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically and clearly defined.

Claims

1. A user privacy protection method based on the Dilithium certificateless blind signature scheme in the vehicle networking, characterized in that, Including: The trusted center generates the system public key, system private key, and system public parameters based on a post-quantum algorithm; The base station of the vehicle-to-everything network initiates a registration request for identity information to the trusted center, and the trusted center generates the first part of the private key and the corresponding tag through a post-quantum algorithm; The base station verifies the first part of the private key according to the received tag; The base station calculates the second part of the private key and generates the complete public-private key pair of the vehicle-to-everything network base station based on the verified first part of the private key, and broadcasts the complete public key in the vehicle-to-everything network; The base station sends a commitment message to the vehicle user, and the vehicle user fuzzifies the privacy data through a blinding factor and then initiates a signature request to the base station; The base station signs the blinded information and returns it to the vehicle user; The vehicle user deblinds the received blinded signature to obtain the true signature for the privacy data; The vehicle user uploads the privacy data and the true signature to the management agency to request authentication; The management agency verifies the true signature of the vehicle user according to the public key broadcast by the base station and stores the privacy data.

2. The method according to claim 1, characterized in that, The trusted center generates the system public key, system private key, and system public parameters based on a post-quantum algorithm, including: Randomly select two random number seeds ρ←{0,1} through the trusted center 256 , K←{0,1} 256 , and respectively obtain the l-order vector s1 and the k-order vector s2 by sampling on the uniform distribution; The trusted center generates a k×l order matrix A = ExpandA(ρ), and calculates a k-order vector t = As1 + s2; The trusted center generates the system public parameters params = {H1, H2, H3, γ1, γ2, β}, where H1, H2, H3 are general hash functions, and γ1, γ2, β are parameters set by the system; The trusted center generates a pair of system public-private key pairs, the system public key pk = (ρ, t), the system private key sk = (ρ, K, s1, s2), and makes the system public key public and sets the system private key to be private.

3. The method according to claim 2, wherein The base station of the vehicle-to-everything network initiates a registration request for identity information to the trusted center, and the trusted center generates the first part of the private key and the corresponding tag through a post-quantum algorithm, including: Send the identity information ID through the base station of the vehicle network s to the trusted center for registration; After registration, the trusted center randomly selects a random number seed ρ1←{0,1} 256 , and calculates an l-order vector Calculate R using a trusted center s = Ar s , and decompose the vector into high and low order bits (R s1 , R s0 ): = Decompose(R s , 2γ2); Use the trusted center to calculate c1 = H1(t||ID s ||R s1 ), and the first part of the private key d s = c1s1 + r s , and send (d s , c1) to the base station applying for registration.

4. The method according to claim 3, wherein The base station verifies the first part of the private key according to the received tag, including: Receiving the first part of the private key d through the base station s and the hash function value c1, and calculating R′ A1 := HighBits(Ad s - c1t, 2γ2); Verify the base station \(c1 = H1(t||ID s ||R s ′1)\) holds. If not, reject the first part of the private key and reapply to the trusted center for the first part of the private key.

5. The method according to claim 4, characterized in that, The base station calculates the second part of the private key and generates the complete public-private key pair of the vehicle-to-everything network base station based on the verified first part of the private key, and broadcasts the complete public key in the vehicle-to-everything network, including: Randomly select two random number seeds ρ2←{0,1} 256 , K1←{0,1} 256 ; Sample a k - order vector x from a uniform distribution s As the second part of the private key of the vehicle terminal Perform high and low order bit calculations on the first part of the private key, (d s1 ,d s0 ):=Power2Round q (d s ,γ3); Calculate w := Ad s0 + x s ; Set the complete public key pk s = w, the complete private key sk s = (K1, ρ2, d s0 , x s ), and broadcast the base station public key pk in the vehicle networking s .

6. The method according to claim 5, characterized in that, The base station sends a commitment message to the vehicle user, and the vehicle user fuzzifies the privacy data through a blinding factor and then initiates a signature request to the base station, including: Selecting an l - order vector using a base station Calculate Y′ = Ay, and send Y′ to the vehicle user as a commitment message; Blindly process the privacy data of vehicle users and select an l - order vector and a random number b ∈ S η , calculate the hash value μ = CRH(ρ||M) for the message M to be sent; Use the vehicle user to calculate the hash value c2 = H2(ID s , pk s , pk), Y1 = HighBit(Y′ + Aa + c2b, 2γ2); The vehicle user verifies LowBit(Y′ + Aa + c2b, 2γ2), if it holds, calculates the signature value e = H3(Y1, μ), and sends the signature value e to the base station to request a signature.

7. The method according to claim 6, wherein The base station signs the blinded information and returns it to the vehicle user, including: Calculate z′ = ed through the base station s0 +y, and reject-sample z′ by sampling, where the sampling method includes verifying ||z′|| by the base station ∞ ≥ γ1 - β holds, where ||z′|| ∞ represents the infinity norm of the vector; The base station sends the signature value z′ to the vehicle user.

8. The method according to claim 7, characterized in that, The vehicle user deblinds the received blinded signature to obtain the true signature for the privacy data, including: After the vehicle user receives the signature value z′, it calculates z = z′ + a; The vehicle user calculates the true signature value σ = (z, e).

9. The method according to claim 8, characterized in that, The vehicle user uploads the privacy data and the true signature to the management agency to request authentication, including: The vehicle user sends the real signature value σ = (z, e) and the message M to the management agency for authentication.

10. The method according to claim 9, characterized in that, The management agency verifies the real signature of the vehicle user according to the public key broadcast by the base station and stores the privacy data, including: After receiving the message M and the signature value σ = (z, e), the management agency calculates the hash value μ = CRH(ρ||M) and the vehicle network public matrix A = ExpandA(ρ); The management agency calculates Y1′ = HighBit(Az-ew, 2γ2) and stores the processed privacy information c2 = H2(ID s , PK s , pk); The management agency verifies e = H3(Y1', μ). If it holds, the signature of the vehicle user passes the authentication.

11. A user privacy protection system based on the Dilithium certificateless blind signature scheme in the vehicle networking, characterized in that, Including: The initialization module is used to generate the system public parameters, the system public key and the system private key by using the trusted center, and publicly disclose the system public parameters and the system public key in the vehicle network, and secretly store the system private key; The first part of the post-quantum private key generation module is used to generate the first part of the private key by using the post-quantum algorithm after the trusted center receives the request for identity registration and the generation of the first part of the private key in the base station of the vehicle network; The second part of the post-quantum private key generation module is used to generate the second part of the private key by using the base station; The complete post-quantum public and private key pair generation module is used to generate the complete post-quantum public and private key pair by using the base station according to the generated first part of the private key and the generated second part of the private key, and broadcast the complete public key in the vehicle network; The blind transformation module is used to blur the privacy data by the vehicle user through the blinding factor; The signature module is used to sign the blinded information by the base station; The de-blinding change module is used to de-blind the received blinded signature by the vehicle user to obtain the real signature for the privacy data; The verification module is used to authenticate the identity of the message and the real signature sent by the vehicle user by the management agency.

Citation Information

Patent Citations

  • Privacy information protection method and system in Internet of Vehicles, and storage medium

    CN117956447A

  • Lattice-based car networking condition privacy protection message authentication method

    CN118118901A