A vehicle-road collaborative system and method based on blockchain
The V2I method using a quantum secure platform and blockchain addresses cross-road segment authentication issues, enhancing data security and efficiency in vehicle communication systems.
Patent Information
- Application Number
- CN202410905397.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-08
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-07-08
AI Technical Summary
The existing anonymous authentication technology for Internet of Vehicles has problems such as low cross-road authentication efficiency, privacy threats caused by anonymity, high authentication complexity and lack of dynamic adaptability, which affects communication efficiency and security.
The vehicle-road collaboration method based on blockchain is adopted to register vehicle identity through the quantum secret service platform, use blockchain to verify vehicle identity, and manage vehicle keys through smart contracts to achieve rapid authentication and information sharing across road sections.
It improves the transparency and security of vehicle identity verification, reduces the redundant verification process, improves communication efficiency and overall efficiency, convenience and scalability of the transportation system, and ensures the privacy protection of vehicle data.
Smart Images

Figure CN118784205B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle networking, and in particular to a vehicle-road collaborative system and method based on blockchain. Background Art
[0002] Within a road section, Roadside Units (RSUs) are usually deployed and managed by the same management agency or organization, which means there is a certain degree of mutual trust among them. The mutual trust among RSUs is mainly manifested in the following aspects: 1) RSUs within a road section usually comply with the same safety standards and protocols, which ensures the reliability and security of communication and data exchange between them; 2) When RSUs perform vehicle authentication and identity verification, they will trust the data and authentication results provided by other RSUs within the road section, so that all RSUs within the road section can effectively identify and authorize vehicles; 3) When an RSU receives traffic information from other RSUs, it will believe the authenticity and reliability of this information. In this way, RSUs can better manage traffic and make decisions, improving the traffic efficiency and safety of the road section.
[0003] In the field of vehicle networking, existing anonymous authentication technologies have a series of problems, which not only affect the efficiency and security of communication, but also threaten the privacy protection of vehicles. Specifically, the problems existing in the prior art mainly include:
[0004] Cross-road-section authentication problem: In vehicle networking, vehicles need to communicate between different road sections. However, existing authentication technologies often only focus on the authentication of a single road section and ignore the cross-road-section authentication problem. When a vehicle enters another road section from one road section, it needs to be re-authenticated, which not only increases the authentication overhead, but also reduces the communication efficiency.
[0005] Anonymity and traceability problem: Although traditional anonymous authentication schemes protect the privacy of users, they also provide opportunities for malicious users to abuse their identities. Attackers may use anonymous identities to commit fraud, slander, spread false information, etc., and it is difficult to be traced and punished.
[0006] Low authentication efficiency: As the number of vehicles in vehicle networking continues to increase, the efficiency requirements for the authentication system are also getting higher and higher. However, some existing authentication technologies have low authentication efficiency due to complex algorithms or reliance on hardware devices, and cannot meet the real-time requirements.
[0007] Lack of dynamic adaptability: Vehicles in vehicle networking move within the ranges of different RSUs, and their communication ranges and states are constantly changing. Therefore, the authentication system needs to have dynamic adaptability and be able to update authentication information in real time. However, some existing authentication technologies lack this dynamic adaptability. Summary of the Invention
[0008] To overcome the defects in the above-mentioned prior art, the present invention provides a vehicle-road cooperation method based on blockchain, which enhances data security and identity authentication transparency, and improves the overall efficiency and convenience of the transportation system.
[0009] To achieve the above object, the present invention adopts the following technical solutions, including:
[0010] A vehicle-road cooperation method based on blockchain, comprising the following steps:
[0011] S1, the identity registration process of the vehicle:
[0012] The vehicle registers its identity with the quantum encryption service platform. After successful identity registration, the quantum encryption service platform uploads the vehicle information to the blockchain.
[0013] S2, the vehicle-road authentication process when the vehicle enters a certain section j:
[0014] The vehicle sends the vehicle information to the roadside device RSUj of this section j to request vehicle-road cooperation; the roadside device RSUj refers to the roadside device that is the blockchain node of this section j.
[0015] The roadside device RSUj retrieves in the blockchain according to the vehicle information to verify the legality of the vehicle identity. After confirming that the vehicle identity is legal, the roadside device RSUj uploads the vehicle-road cooperation permission information of the vehicle to the blockchain and generates a blockchain index BI; at the same time, the roadside device RSUj also obtains the vehicle key CK from the vehicle information, and the roadside device RSUj sends the vehicle-road cooperation permission information and the vehicle key CK of the vehicle to all other roadside devices within this section j; subsequently, the vehicle uses the vehicle key CK for communication within this section j.
[0016] S3, the vehicle-road authentication process when the vehicle leaves this section j and enters the next section, i.e., section k:
[0017] The vehicle sends a departure request to the roadside device RSUj of section j. The roadside device RSUj generates a section key LK and generates a smart contract containing the section key LK to obtain the address POS that uniquely identifies the smart contract; the roadside device RSUj sends the blockchain index BI, the section key LK, and the address POS to the vehicle.
[0018] After the vehicle enters section k, the vehicle sends the blockchain index BI and the address POS to the roadside device RSUk of section k to request vehicle-road cooperation; after the roadside device RSUk retrieves in the blockchain according to the blockchain index BI and obtains the vehicle-road cooperation permission information of the vehicle, the roadside device RSUk finds the smart contract through the address POS and obtains the section key LK; the roadside device RSUk sends the vehicle-road cooperation permission information of the vehicle and the section key LK to all other roadside devices within the section k; subsequently, the vehicle uses the section key LK to communicate within the section k.
[0019] Preferably, the specific process of step S1 is as follows:
[0020] S11, the vehicle generates a vehicle random number RNi, and sends the vehicle's unique identity code VINi and the vehicle random number RNi to the quantum encryption service platform;
[0021] S12, the quantum encryption service platform generates a platform random number RNx, calculates the vehicle's anonymity ANC using the vehicle's unique identity code VINi, the vehicle random number RNi, and the platform random number RNx, where RNi and RNx are anonymity parameters, and calculates the check code AC corresponding to the anonymity ANC according to RNi and RNx, and uses the private key of the quantum encryption service platform to sign the vehicle's anonymity ANC and the check code AC to generate a signature value Signt. Finally, the quantum encryption service platform uploads the data {ANC, AC, Signt} to the blockchain; at the same time, the quantum encryption service platform sends the platform random number RNx to the vehicle;
[0022] S13, the vehicle calculates the vehicle's anonymity ANC according to the vehicle's unique identity code VINi, the vehicle random number RNi, and the platform random number RNx, and calculates the vehicle key CK according to RNi and RNx.
[0023] Preferably, in step S2, the vehicle sends the anonymity ANC and the corresponding anonymity parameters RNi and RNx to the roadside device RSUj of section j to request vehicle-road cooperation; the roadside device RSUj retrieves the transaction data {ANC, AC, Signt} in the blockchain according to the vehicle's anonymity ANC, and uses the public key of the quantum encryption service platform to verify the signature value Signt to verify the correct integrity of the ANC and AC stored in the blockchain, and calculates and verifies the check code AC using the RNi and RNx sent by the vehicle to verify the legality of the vehicle's identity.
[0024] Preferably, in step S2, after confirming the legality of the vehicle's identity, the roadside device RSUj uploads the data {ANC, permit, Signj} to the blockchain and generates a blockchain index BI;
[0025] Among them, permit is the vehicle-road collaborative permission information of the vehicle; Signj is the signature value generated by signing ANC and permit using the private key of the roadside device RSUj of the node.
[0026] Preferably, in step S2, after the vehicle enters the communication range of section j, it receives the digital certificate of the roadside device rj1 closest to the vehicle in section j through broadcasting, and obtains the public key of the roadside device rj1.
[0027] The specific process of step S2 is as follows:
[0028] S21, the vehicle encrypts the anonymous parameters RNi and RNx using the public key of the roadside device rj1 to obtain the encrypted message m3, combines the anonymous ANC, the encrypted message m3, and the authentication request AddReq to generate the message body M3, M3 = [AddReq, ANC, m3]; the vehicle broadcasts the message body M3 to the roadside device rj1.
[0029] S22, after the roadside device rj1 receives the authentication request message, that is, the message body M3, it obtains the vehicle's anonymous ANC and the encrypted message m3, and decrypts the encrypted message m3 using the private key of the roadside device rj1 to obtain the anonymous parameters RNi and RNx.
[0030] Judge whether the roadside device rj1 is the node roadside device RSUj of section j. If so, go to step S23; if not, the roadside device rj1 first encrypts the anonymous parameters RNi and RNx using the preset shared key SPj in section j to obtain the encrypted message m4, m4 = SPj(RNi, RNx), then combines the vehicle's anonymous ANC, the encrypted message m4, and the authentication request AddReq to generate the message body M4, M4 = [AddReq, ANC, m4], and the roadside device rj1 sends the message body M4 to the node roadside device RSUj of section j, and enters step S23.
[0031] S23, after the node roadside device RSUj of section j obtains the vehicle's anonymous ANC, and decrypts to obtain the anonymous parameters RNi and RNx, the following operations are performed:
[0032] S231, the node roadside device RSUj retrieves the transaction data {ANC, AC, Signt} in the blockchain according to the vehicle's anonymous ANC, and uses the public key of the quantum encryption service platform to verify the quantum encryption service platform signature value Signt to verify the correct integrity of ANC and AC stored in the blockchain.
[0033] S232, the roadside unit RSUj of the node calculates the check code AC using RNi and RNx, and determines whether the calculated check code AC is equal to the check code AC in the transaction data. If not, the vehicle identity is illegal; if so, the vehicle identity is legal. The roadside unit RSUj of the node uploads the data {ANC, permit, Signj} to the blockchain and generates a blockchain index BI;
[0034] wherein, permit is the vehicle-road collaborative permission information of the vehicle; Signj is the signature value generated by signing ANC and permit using the private key of the roadside unit RSUj of the node;
[0035] S233, the roadside unit RSUj of the node calculates the vehicle key CK according to RNi and RNx, encrypts the vehicle key CK using the pre-shared key SPj to generate an encrypted message m5, and the roadside unit RSUj of the node generates a message body M5, M5 = [ANC, permit, m5, Signj], and sends the message body M5 to all other roadside units within the section j;
[0036] S24, after receiving the message body M5, other roadside units within the section j verify the signature value Signj using the public key of the roadside unit RSUj of the node, and decrypt the encrypted message m5 using the pre-shared key SPj to obtain the vehicle key CK; subsequently, the vehicle uses the vehicle key CK for vehicle-road communication within the section j.
[0037] Preferably, the specific process of step S3 is as follows:
[0038] S31, the vehicle broadcasts a departure request message within the section j. After receiving the departure request message, the roadside unit rj2 closest to the vehicle in the section j determines whether the roadside unit rj2 is the roadside unit RSUj of the node in the section j. If so, it proceeds to step S32; if not, the roadside unit rj2 first encrypts the departure request message using the pre-shared key SPj and sends it to the roadside unit RSUj of the node, and proceeds to step S32;
[0039] S32. After the roadside unit RSUj of the node of section j receives the departure request message of the vehicle, the roadside unit RSUj of the node generates a section key LK, generates a smart contract containing the section key LK, and obtains the address POS that uniquely identifies the smart contract; encrypts the blockchain index BI, the section key LK, the address POS, and the current timestamp Ts7 with the vehicle key CK to obtain an encrypted message m7, m7 = CK(BI, LK, POS, Ts7). The roadside unit RSUj of the node uses the private key of the roadside unit RSUj of the node to sign the encrypted message m7 to generate a signature value S7. The roadside unit RSUj of the node generates a message body M7, M7 = [ANC, m7, S7, Ts7], and the roadside unit RSUj of the node sends the message body M7 to the vehicle;
[0040] S33. After the vehicle receives the message body M7, it verifies the message body M7, including: judging the message validity through the timestamp Ts7 in the message body M7, and verifying the signature value S7 in the message body M7 with the public key of the roadside unit RSUj of the node; after the message body M7 is successfully verified, the vehicle decrypts the encrypted message m7 with the vehicle key CK to obtain the blockchain index BI, the key LK, and the address POS.
[0041] Preferably, after step S33, the following specific process is further included:
[0042] S34. After the vehicle enters the next section, i.e., section k, it receives the digital certificate of the roadside unit rk1 closest to the vehicle in section k through broadcasting and obtains the public key of the roadside unit rk1; the vehicle encrypts the blockchain index BI and the address POS with the public key of the roadside unit rk1 to obtain an encrypted message m8, and the vehicle combines the anonymous ANC, the encrypted message m8, and the authentication request AddReq to generate a message body M8, M8 = [AddReq, ANC, m8]; the vehicle sends the message body M8 to the roadside unit rk1 through broadcasting;
[0043] S35. After the roadside unit rk1 receives the authentication request message, i.e., the message body M8, it obtains the anonymous ANC and the encrypted message m8 of the vehicle, and decrypts the encrypted message m8 with the private key of the roadside unit rk1 to obtain the blockchain index BI and the address POS;
[0044] Determine whether the roadside device rk1 is the node roadside device RSUk of this road section k. If so, proceed to step S36; if not, the roadside device rk1 first uses the preset shared key SPk within road section k to encrypt the blockchain index BI and the address POS to obtain the encrypted message m9, where m9 = SPk(BI,POS). Then, combine the vehicle's anonymity ANC, the encrypted message m9, and the authentication request AddReqk to generate the message body M9, where M9 = [AddReq,ANC,m9]. The roadside device rk1 sends the message body M9 to the node roadside device RSUk of this road section k and proceeds to step S36;
[0045] S36. After the node roadside device RSUk of this road section k obtains the vehicle's anonymity ANC, decrypts to obtain the blockchain index BI and the address POS, perform the following operations:
[0046] S361. The node roadside device RSUk retrieves in the blockchain according to the blockchain index BI, and retrieves the transaction data {ANC,permit,Signj} of the vehicle identity verification by the node roadside device RSUj of the previous road section, i.e., road section j, and verifies the signature value Signj using the public key of the node roadside device RSUj;
[0047] S362. Find the smart contract through the address POS, and upload the transaction data {ANC,permit,Signj} to the blockchain to trigger the smart contract, and the smart contract returns the road section key LK to the node roadside device RSUk;
[0048] S363. The node roadside device RSUk sends the vehicle's vehicle-road cooperation permission information and the road section key LK to all other roadside devices within this road section k;
[0049] S37. The vehicle performs vehicle-road communication within this road section k using the road section key LK.
[0050] Preferably, in step S1, during the vehicle identity registration process, the quantum encryption service platform also limits the validity period of the vehicle identity registration and uploads the validity period to the blockchain as well.
[0051] Preferably, in step S2, during the process of the node roadside device RSUj verifying the legality of the vehicle identity, it also retrieves the validity period of the vehicle identity registration in the blockchain and determines whether it exceeds the validity period.
[0052] The present invention also provides a vehicle-road cooperation system based on blockchain, which is applied to the above-mentioned vehicle-road cooperation method based on blockchain. The system includes: a quantum encryption service platform, a road section, a vehicle, and a blockchain;
[0053] The quantum encryption service platform is responsible for issuing and managing digital certificates, generating vehicle anonymity and registering vehicle identities in the blockchain, and managing the blockchain;
[0054] The road section includes multiple roadside devices for verifying vehicle identities and vehicle-road collaboration; the node roadside devices in the road section are used to create transactions and deploy smart contracts on the blockchain.
[0055] The advantages of the present invention are as follows:
[0056] (1) By verifying vehicle identities through the blockchain, a more secure and trustworthy environment can be provided for vehicle-road sharing and data exchange, enhancing data security and authentication transparency. Vehicles can directly interact with other vehicles or traffic management systems through authentication to share driving data, road condition information, etc., promoting cooperation and mutual trust between intelligent transportation and vehicles. The transaction and authentication records on the blockchain are public and can be accessed by all nodes. This transparency can provide traceability and verifiability for the vehicle identity authentication process, preventing fraud and illegal behavior.
[0057] (2) If each roadside device in a road section needs to independently verify vehicle identities, it will increase the complexity of management and maintenance. After a vehicle's identity is verified by a node roadside device in the present invention, other roadside devices in the same road section can trust the verification result and do not need to verify the vehicle again. This reduces redundant verification processes, can significantly reduce communication overhead and bandwidth consumption, improve communication efficiency and system stability, making the driving and related operations of the vehicle in the road section more seamless and efficient, and at the same time enhancing the overall efficiency and convenience of the traffic system.
[0058] (3) To ensure data security and privacy protection when a vehicle enters a road section, the present invention adopts anonymity protection measures.
[0059] (4) When a vehicle enters the next road section from a road section where its identity has been verified, it needs to be re-authenticated to ensure security. At the same time, to reduce the repeated identity verification process and achieve rapid authentication between the vehicle and the road section, the present invention uses the blockchain network and smart contracts for information sharing and transmission. In this way, after a vehicle is authenticated in a road section, the verification result can be stored on the blockchain, and key transfer can be achieved through smart contracts. With the help of the blockchain, rapid cross-road-section vehicle authentication is realized, and with the help of smart contracts, the management of vehicle-road collaboration keys is realized, improving the efficiency of vehicle-road collaboration.
[0060] (5) Using the blockchain for vehicle identity verification can reduce operation complexity. It does not require verification by a traditional centralized authorization agency, is decentralized to a certain extent, reduces intermediate links, and improves efficiency.
[0061] (6) The road is divided into sections, and different sections are operated and managed through different network nodes, which disperses the load of the traffic system, improves the scalability of the traffic system, and can better meet the management requirements of large-scale traffic networks.
[0062] (7) The authentication information of vehicles by roadside devices of nodes is recorded on the blockchain. Since the blockchain is a private chain and the roadside devices have no permission, when the review authority traces, the authentication records can be obtained from the blockchain, and the anonymous identity of the vehicle can be obtained from the quantum encryption service platform to achieve traceability. Description of the Drawings
[0063] Figure 1 It is an architecture diagram of a vehicle-road collaborative system based on blockchain.
[0064] Figure 2 It is a flowchart of a vehicle-road collaborative method based on blockchain. Detailed Embodiments
[0065] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0066] In the vehicle-road collaborative scenario of the present invention, the road is divided into different sections. All roadside devices within the same section trust each other with the authenticated vehicles within the section, but new vehicles entering the section cannot directly join the vehicle-road collaboration. Therefore, the new vehicle needs to authenticate its identity with the roadside devices within the section.
[0067] As Figure 1 shown, a vehicle-road collaborative system based on blockchain includes: a quantum encryption service platform, sections, vehicles, and a blockchain.
[0068] The Quantum Cryptographic Service Platform is used for issuing and managing digital certificates, generating vehicle anonymity and registering vehicle identities in the blockchain, as well as managing the blockchain. The Quantum Cryptographic Service Platform includes: a Certification Authority (CA), an Anonymous Credential Generation Server, and a Blockchain Client. Among them, the Certification Authority (CA) is a certification authority trusted by both vehicles and roadside devices. The CA issues digital certificates for vehicles and roadside devices respectively according to their unique identifiers, and manages the digital certificates, which contain the corresponding public key information. The Anonymous Credential Generation Server generates n anonymities for vehicles to protect vehicle privacy. The Blockchain Client is used to create blockchain transactions, write vehicle anonymities into the blockchain, digitally sign the transactions using its private key to ensure the integrity of the transactions and the authenticity of the identities. The signed transactions are broadcast to the nodes in the blockchain network. Once consensus is reached, the transactions will be packed into a new block and added to the blockchain. Through the above process, the identity information of the vehicle will be permanently written into the blockchain and become an immutable record, which can be queried and verified by other nodes participating in the blockchain network.
[0069] A section contains multiple roadside devices for verifying vehicle identities and vehicle-road collaboration. All roadside devices in a section are connected by wire and pre-set with a shared key. One of the roadside devices serves as a node in the blockchain network, verifies the vehicle's legitimacy by querying the vehicle identity in the blockchain, and shares the result with all roadside devices in this section.
[0070] The vehicle is given a piece of true random number generated by a quantum random number generator as the vehicle's unique identifier, the VIN code, at the factory stage. At the same time, it is equipped with an OBU device (On-Board Unit) and a quantum random number generator. The vehicle can communicate with roadside devices through broadcasting, and can also complete information interaction with other vehicles equipped with OBU devices.
[0071] Blockchain is a distributed and immutable technology for recording information. A blockchain consists of a series of data blocks linked together, and each data block contains multiple transactions or information records. Each data block contains a reference to the previous data block, forming a chain structure that makes the data unable to be deleted or tampered with. Blockchain uses a consensus mechanism to solve the data consistency problem and ensure that each node on the network reaches a consistent data state. Due to the distributed and decentralized characteristics of blockchain, no single entity can control the entire network, making the data more secure and transparent. A smart contract is an automated contract written in the form of computer code that executes the contract terms on the blockchain. Smart contracts utilize the decentralization and immutability of blockchain to automatically execute the conditions and operations agreed upon in the contract through programming code. As the manager of the blockchain, the Quantum Secret Service Platform authorizes the roadside devices of the nodes to create transactions and deploy smart contracts. At the same time, it can manage the revocation of vehicle identities and the revocation of roadside devices of nodes within the blockchain, as well as achieve traceability.
[0072] As shown by Figure 2 A vehicle-road collaborative method based on blockchain includes the following steps:
[0073] S1. The vehicle identity registration process is as follows:
[0074] S11. The quantum random number generator of the vehicle generates n vehicle random numbers RNi. These n vehicle random numbers RNi are denoted as {RNi}n. The vehicle first encrypts the vehicle's unique identity code VINi, {RNi}n, and the current timestamp Ts1 using the public key PKc of the Quantum Secret Service Platform to obtain the encrypted message m1 = PKc(VINi, {RNi}n, Ts1); then uses the vehicle's private key to sign the encrypted message m1 to generate the signature value S1, and generates the prefix identifier tag1 using the message type for requesting identity registration; finally, obtains the message body M1 based on the prefix identifier tag1, the encrypted message m1, the signature value S1, and the timestamp Ts1. M1 = [tag1, m1, S1, Ts1]; the vehicle sends the message body M1 to the Quantum Secret Service Platform.
[0075] S12. After receiving the vehicle identity registration request message, that is, the message body M1, the Quantum Secret Service Platform performs the following operations:
[0076] S121. The quantum encryption service platform verifies the message body M1: First, it determines the message validity through the timestamp Ts1 at the end of the message body M1. If the time difference between the timestamp Ts1 and the current time is greater than the preset time threshold, it means the message is invalid and no subsequent processing is performed; otherwise, it means the message is valid, and the quantum encryption service platform continues the processing. Then, it verifies the signature value S1 in the message body M1 using the vehicle public key. It decrypts the signature value S1 in the message body M1 using the vehicle public key. If the decrypted content of the signature value S1 is inconsistent with the encrypted message m1 in the message body M1, the signature verification fails and no subsequent processing is performed; otherwise, the signature verification is successful, confirming that the message body M1 is indeed generated by the sending vehicle, and the quantum encryption service platform continues the processing.
[0077] S122. The quantum encryption service platform decrypts the encrypted message m1 using the private key of the quantum encryption service platform to obtain the content in the encrypted message m1, getting the vehicle's unique identification code VINi and n vehicle random numbers RNi. At the same time, it verifies whether the timestamp Ts1 in the encrypted message m1 is consistent with the timestamp Ts1 at the end of the message body M1 to determine whether the message is replayed during transmission. If the timestamp Ts1 in the encrypted message m1 is inconsistent with the timestamp Ts1 at the end of the message body M1, it means the message is replayed and no subsequent processing is performed; otherwise, it means the message is not replayed, and the quantum encryption service platform continues the processing.
[0078] S123. The quantum encryption service platform verifies the vehicle's unique identification code VINi obtained by decryption, determining whether the vehicle's unique identification code VINi obtained by decryption is equal to the vehicle's unique identification code VINi stored in the database. If they are not equal, it means the vehicle's identity authentication fails and no subsequent processing is performed; otherwise, it means the vehicle's identity authentication is successful, and the quantum encryption service platform continues the processing;
[0079] S124. The quantum encryption service platform generates n platform random numbers RNx, denoted as {RNx}n, and calculates the vehicle's n anonymizations ANC = H(VINi, RNi, RNx) using the vehicle's unique identification code VINi, n vehicle random numbers RNi, and n platform random numbers RNx. The vehicle random numbers RNi and platform random numbers RNx are the anonymization parameters. It calculates the check code AC = H(RNi || RNx) corresponding to the anonymization ANC based on RNi and RNx, and uses the private key of the quantum encryption service platform to sign ANC || AC to generate the signature value Signt. Finally, the quantum encryption service platform uploads the data {ANC, AC, Signt} to the blockchain. Here, || is the exclusive OR operation, and H(·) is the hash function.
[0080] S125. First, the quantum encryption service platform encrypts n platform random numbers RNx and the current timestamp Ts2 using the vehicle's public key PKi to obtain the encrypted message m2 = PKi({RNx}n, Ts2). Then, it signs the encrypted message m2 using the quantum encryption service platform's private key to generate the signature value S2, and generates the prefix identifier tag2 using the message type returned for identity registration. Finally, it obtains the message body M2 based on the prefix identifier tag2, the encrypted message m2, the signature value S2, and the timestamp Ts2, where M2 = [tag2, m2, S2, Ts2]. The quantum encryption service platform sends the message body M2 to the vehicle.
[0081] S13. After the vehicle receives the identity registration return message from the quantum encryption service platform, i.e., the message body M2, it performs the following operations:
[0082] S131. The vehicle verifies the message body M2. First, it determines the message validity by the timestamp Ts2 at the end of the message body M2, and then verifies the signature value S2 in the message body M2 using the public key of the quantum encryption service platform. The specific verification method refers to step S121, and in this embodiment, the subsequent message validity verification and signature value verification methods are the same as those in step S121.
[0083] S132. The vehicle decrypts the encrypted message m2 using the vehicle's private key to obtain the content in the encrypted message m2, i.e., the n platform random numbers RNx of the quantum encryption service platform. At the same time, it verifies whether the message has been replayed during transmission based on the timestamp Ts2 in the encrypted message m2. The specific verification method refers to step S122, and in this embodiment, the subsequent message replay verification method is the same as that in step S121.
[0084] S133. The vehicle uses the vehicle's unique identity code VINi, n vehicle random numbers RNi, and n platform random numbers RNx to calculate the vehicle's n anonymized values ANC = H(VINi, RNi, RNx), and calculates the vehicle key CK corresponding to the vehicle anonymized value ANC = H(RNi, RNx).
[0085] During the vehicle's identity registration process, the quantum encryption service platform also defines the validity period of the vehicle's identity registration, i.e., the validity period of the vehicle anonymized value ANC, and the quantum encryption service platform uploads the validity period of the vehicle anonymized value ANC to the blockchain.
[0086] S2. The vehicle-road authentication process when the vehicle enters a certain section j is as follows:
[0087] After the vehicle drives into the communication range of section j, it receives the digital certificate of the roadside device rj1 closest to the vehicle in section j through PC5 broadcast, verifies the identity legality of the roadside device rj1, and obtains the public key of the roadside device rj1.
[0088] S21. The vehicle selects one of its own anonymous ANCs and the corresponding anonymous parameters RNi and RNx, encrypts the anonymous parameters RNi and RNx using the public key Sprj1 of the roadside device rj1 to obtain the encrypted message m3, where m3 = Sprj1(RNi, RNx). The vehicle combines the selected anonymous ANC, the encrypted message m3, and the authentication request AddReq to generate the message body M3, where M3 = [AddReq, ANC, m3]. The vehicle broadcasts the message body M3 to the roadside device rj1 via PC5.
[0089] S22. After receiving the authentication request message, i.e., the message body M3, the roadside device rj1 obtains the vehicle's anonymous ANC and the encrypted message m3, and decrypts the encrypted message m3 in the message body M3 using the private key of the roadside device rj1 to obtain the anonymous parameters RNi and RNx.
[0090] It is determined whether the roadside device rj1 is the node roadside device RSUj of this section. The node roadside device RSUj refers to the roadside device that is a blockchain node of section j of this road. If the roadside device rj1 is the node roadside device RSUj, then step S23 is entered; otherwise, the roadside device rj1 first encrypts the anonymous parameters RNi and RNx using the pre-shared key SPj within section j to obtain the encrypted message m4, where m4 = SPj(RNi, RNx), then combines the vehicle's anonymous ANC, the encrypted message m4, and the authentication request AddReq to generate the message body M4, where M4 = [AddReq, ANC, m4]. The roadside device rj1 sends the message body M4 to the node roadside device RSUj of this section via wired transmission and enters step S23.
[0091] S23. After the node roadside device RSUj of this section obtains the vehicle's anonymous ANC and decrypts to obtain the anonymous parameters RNi and RNx, the following operations are performed:
[0092] S231. The node roadside device RSUj retrieves the transaction data {ANC, AC, Signt} in the blockchain according to the vehicle's anonymous ANC. The node roadside device RSUj checks the validity period of the vehicle's anonymous ANC to ensure that the transaction is still valid, and verifies the quantum service platform signature value Signt using the public key of the quantum service platform to verify the correct integrity of the ANC and AC stored in the blockchain.
[0093] S232. The roadside device RSUj of the node calculates the check code AC = H(RNi||RNx) using the anonymous parameters RNi and RNx, and compares whether the calculated check code AC is equal to the AC retrieved from the blockchain for the transaction. If they are not equal, it means the anonymous identity of the vehicle is illegal and no subsequent processing is performed; otherwise, it means the anonymous identity of the vehicle is legal. The roadside device RSUj of the node performs subsequent processing. The roadside device RSUj of the node uploads the data {ANC, permit, Signj} to the blockchain and generates a blockchain index BI.
[0094] Among them, permit is the vehicle-road cooperation permission information of the vehicle, that is, the permission information allowing the vehicle to perform vehicle-road cooperation; Signj is the signature value generated by the roadside device RSUj of the node by signing ANC and permit using its private key. The signature process is specifically to first perform a hash calculation on ANC and permit to obtain a hash value, and then use the private key to encrypt the hash value to obtain the signature value. Subsequently, the signature verification process is specifically as follows: The receiving party first decrypts the signature value using the public key of the sending party to obtain the hash value, and then determines whether the hash value obtained by performing a hash calculation on ANC and permit is consistent with the decrypted hash value.
[0095] S233. The roadside device RSUj of the node calculates the vehicle key CK = H(RNi, RNx) corresponding to the vehicle's anonymity ANC, and encrypts the vehicle key CK using the pre-shared key SPj within section j to generate an encrypted message m5, m5 = SPj(CK). The roadside device RSUj of the node generates a message body M5 based on the vehicle anonymity ANC, permit, encrypted message m5, and Signj, M5 = [ANC, permit, m5, Signj], and sends the message body M5 to all other roadside devices within this section j through wired transmission.
[0096] S24. After the other roadside devices within section j receive the message body M5 through broadcast, after verifying the signature value Signj of the roadside device RSUj of the node, they believe that the identity of the vehicle is legal. The roadside device that confirms the legal identity of the vehicle and obtains the vehicle key CK broadcasts the message {ANC, permit, Signj} to the vehicle so that the vehicle can obtain the identity verification of vehicle-road cooperation in this section. In addition, other roadside devices decrypt the encrypted message m5 using the pre-shared key SPj to obtain the vehicle key CK, which can be used to directly perform vehicle-road cooperation communication with the vehicle or for new session key distribution to achieve communication with other vehicles within the section.
[0097] S3. The vehicle-road authentication process when the vehicle leaves section j and enters the next section, that is, section k, is specifically as follows:
[0098] S31, The vehicle broadcasts the message body M6 = [AddReq for leave, ANC] for leaving the road section j to the roadside device of the road section j. AddReq for leave represents the request for the vehicle to leave the road section. After receiving the message body M6, the roadside device rj2 closest to the vehicle in the road section j determines whether the roadside device rj2 is the node roadside device RSUj of the road section. If the roadside device rj2 is the node roadside device RSUj, it proceeds to step S32; otherwise, the roadside device rj2 first encrypts the message body M6 using the preset shared key SPj and sends it to the node roadside device RSUj of the road section j via wired transmission, and then proceeds to step S32;
[0099] S32, The node roadside device RSUj of the road section j generates a random number RNj, calculates the road section key LK = H(RNj) using the random number RNj, and generates a smart contract containing the road section key LK to obtain the address POS that uniquely identifies the smart contract. The vehicle key CK is used to encrypt the blockchain index BI, key LK, address POS, and the current timestamp Ts7 to obtain the encrypted message m7, m7 = CK(BI, LK, POS, Ts7). The private key of the node roadside device RSUj is used to sign the encrypted message m7 to generate the signature value S7. The node roadside device obtains the message body M7 based on the vehicle's anonymity ANC, encrypted message m7, signature value S7, and timestamp Ts7, M7 = {ANC, m7, S7, Ts7}. The node roadside device RSUj sends the message body M7 to the vehicle.
[0100] S33, After receiving the message body M7, the vehicle verifies the message body M7: first, it determines the message validity through the timestamp Ts7 at the end of the message body M7, and then verifies the signature value S7 in the message body M7 using the public key of the node roadside device RSUj. After the message body M7 is successfully verified, the vehicle decrypts the encrypted message m7 using the vehicle key CK to obtain the blockchain index BI, key LK, and address POS.
[0101] S34, When the vehicle enters the next road section, i.e., road section k, it broadcasts and receives the digital certificate of the roadside device rk1 closest to the vehicle in the road section k through PC5, verifies the identity legality of the roadside device rk1 and obtains the public key of the roadside device rk1. The vehicle uses the public key Sprk1 of the roadside device rk1 to encrypt the blockchain index BI and address POS to obtain the encrypted message m8 = Sprk1(BI, POS). The vehicle combines the anonymity ANC, encrypted message m8, and authentication request AddReq to generate the message body M8, M8 = [AddReq, ANC, m8]. The vehicle sends the message body M8 to the roadside device rk1 via PC5 broadcast.
[0102] S35. After the roadside device rk1 receives the authentication request message, i.e., the message body M8, it obtains the vehicle's anonymous ANC and the encrypted message m8. It uses the private key of the roadside device rk1 to decrypt the encrypted message m8 in the message body M8 to obtain the blockchain index BI and the address POS.
[0103] It is determined whether the roadside device rk1 is the node roadside device RSUk of this road section k. If the roadside device rk1 is the node roadside device RSUk, it proceeds to step S36; otherwise, the roadside device rk1 first uses the pre-set shared key SPk within the road section k to encrypt the blockchain index BI and the address POS to obtain the encrypted message m9, m9 = SPk(BI, POS). Then, it combines the vehicle's anonymous ANC, the encrypted message m9, and the authentication request AddReq to generate the message body M9, M9 = [AddReq, ANC, m9]. The roadside device rk1 sends the message body M9 to the node roadside device RSUk via wired transmission and proceeds to step S36.
[0104] S36. After the node roadside device RSUk obtains the vehicle's anonymous ANC, and decrypts to obtain the blockchain index BI and the address POS, the following operations are performed:
[0105] S361. The node roadside device RSUk retrieves in the blockchain according to the blockchain index BI, and retrieves the transaction data of the vehicle identity authentication by the node roadside device RSUj of the previous road section, i.e., the road section j, which is {ANC, permit, Signj}, and uses the public key of the node roadside device RSUj to verify the signature value Signj, believing that the vehicle's anonymous identity is legal.
[0106] S362. Find the smart contract through the address POS, and upload the transaction data {ANC, permit, Signj} to the blockchain to trigger the smart contract, and the smart contract returns the road section key LK to the node roadside device RSUk.
[0107] S363. The node roadside device RSUk sends the vehicle's vehicle-road cooperation permission information and the road section key LK to all other roadside devices within this road section k.
[0108] S37. The vehicle performs vehicle-road communication within this road section k using the road section key LK.
[0109] In addition, the node roadside device RSUk needs to upload the data {ANC, permit, Signk} to the blockchain and generate the blockchain index BI; where Signk is the signature value generated by using the private key of the node roadside device RSUk to sign ANC and permit.
[0110] Through the above method, efficient vehicle-road cooperation can be achieved between the vehicle and the road section, ensuring the safe passage of the vehicle. At the same time, through the anonymous protection measures, the data privacy of the vehicle can also be effectively protected. Overall, the use of blockchain networks and smart contracts can achieve rapid authentication and information sharing between the vehicle and the road section, promoting good vehicle-road cooperation.
[0111] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A vehicle-road cooperation method based on blockchain, characterized in that It includes the following steps: S1. Vehicle identity registration process: The vehicle conducts identity registration with the quantum security service platform. After successful identity registration, the quantum security service platform uploads the vehicle information to the blockchain; S2. Vehicle-road authentication process when the vehicle enters a certain section j: The vehicle sends the vehicle information to the roadside device RSUj of the node in this section j to request vehicle-road cooperation; The roadside device RSUj of the node refers to the roadside device that is the blockchain node of this section j; The roadside device RSUj of the node retrieves in the blockchain based on the vehicle information to verify the legality of the vehicle identity. After confirming the legal vehicle identity, the roadside device RSUj of the node uploads the vehicle-road cooperation permission information of the vehicle to the blockchain and generates a blockchain index BI; meanwhile, the roadside device RSUj of the node also obtains the vehicle key CK from the vehicle information, and the roadside device RSUj of the node sends the vehicle-road cooperation permission information of the vehicle and the vehicle key CK to all other roadside devices in this section j; subsequently, the vehicle uses the vehicle key CK for communication within this section j; S3. Vehicle-road authentication process when the vehicle leaves this section j and enters the next section, i.e., section k: The vehicle sends a departure request to the roadside device RSUj of section j. The roadside device RSUj of the node generates a section key LK and generates a smart contract containing the section key LK to obtain the address POS that uniquely identifies the smart contract; The roadside device RSUj of the node sends the blockchain index BI, the section key LK, and the address POS to the vehicle; After the vehicle enters section k, the vehicle sends the blockchain index BI and the address POS to the roadside device RSUk of section k to request vehicle-road cooperation; The roadside device RSUk of the node retrieves in the blockchain based on the blockchain index BI. After obtaining the vehicle-road cooperation permission information of the vehicle, the roadside device RSUk of the node finds the smart contract through the address POS and obtains the section key LK; the roadside device RSUk of the node sends the vehicle-road cooperation permission information of the vehicle and the section key LK to all other roadside devices in this section k; subsequently, the vehicle uses the section key LK for communication within this section k.
2. The vehicle-road collaborative method based on blockchain according to claim 1, wherein The specific process of step S1 is as follows: S11. The vehicle generates a vehicle random number RNi and sends the vehicle identity unique identification code VINi and the vehicle random number RNi to the quantum security service platform; S12. The quantum security service platform generates a platform random number RNx, calculates the vehicle anonymity ANC using the vehicle identity unique identification code VINi, the vehicle random number RNi, and the platform random number RNx, where RNi and RNx are anonymity parameters, calculates the check code AC corresponding to the anonymity ANC according to RNi and RNx, and generates a signature value Signt by signing the vehicle anonymity ANC and the check code AC using the private key of the quantum security service platform. Finally, the quantum security service platform uploads the data {ANC, AC, Signt} to the blockchain; meanwhile, the quantum security service platform sends the platform random number RNx to the vehicle; S13. The vehicle calculates the vehicle's anonymous ANC based on the vehicle's unique identification code VINi, the vehicle random number RNi, and the platform random number RNx, and calculates the vehicle key CK based on RNi and RNx.
3. The vehicle-road collaboration method based on blockchain according to claim 2, characterized in that, In step S2, the vehicle sends the anonymous ANC and the corresponding anonymous parameters RNi and RNx to the node roadside unit RSUj of section j to request vehicle-road cooperation. The node roadside unit RSUj retrieves the transaction data {ANC, AC, Signt} in the blockchain based on the vehicle's anonymous ANC, and uses the public key of the quantum encryption service platform to verify the signature value Signt to verify the correct integrity of ANC and AC stored in the blockchain, and calculates and verifies the check code AC using RNi and RNx sent by the vehicle to verify the legality of the vehicle's identity.
4. The vehicle-road collaborative method based on blockchain according to claim 2, characterized in that, In step S2, after confirming the legality of the vehicle's identity, the node roadside unit RSUj uploads the data {ANC, permit, Signj} to the blockchain and generates a blockchain index BI. Among them, permit is the vehicle-road cooperation permission information of the vehicle; Signj is the signature value generated by signing ANC and permit using the private key of the node roadside unit RSUj.
5. The vehicle-road collaborative method based on blockchain according to claim 2, wherein In step S2, after the vehicle enters the communication range of section j, it receives the digital certificate of the roadside unit rj1 closest to the vehicle in this section j through broadcasting and obtains the public key of this roadside unit rj1. The specific process of step S2 is as follows: S21. The vehicle encrypts the anonymous parameters RNi and RNx using the public key of the roadside unit rj1 to obtain the encrypted message m3, combines the anonymous ANC, the encrypted message m3, and the authentication request AddReq to generate the message body M3, M3 = [AddReq, ANC, m3]; the vehicle sends the message body M3 to the roadside unit rj1 through broadcasting. S22. After the roadside unit rj1 receives the authentication request message, that is, the message body M3, it obtains the vehicle's anonymous ANC and the encrypted message m3, and uses the private key of the roadside unit rj1 to decrypt the encrypted message m3 to obtain the anonymous parameters RNi and RNx. Judge whether the roadside unit rj1 is the node roadside unit RSUj of this section j. If so, enter step S23; if not, the roadside unit rj1 first encrypts the anonymous parameters RNi and RNx using the pre-shared key SPj in section j to obtain the encrypted message m4, m4 = SPj(RNi, RNx), and then combines the vehicle's anonymous ANC, the encrypted message m4, and the authentication request AddReq to generate the message body M4, M4 = [AddReq, ANC, m4]. The roadside unit rj1 sends the message body M4 to the node roadside unit RSUj of this section j and enters step S23. S23. After the node roadside unit RSUj of this section j obtains the vehicle's anonymous ANC and decrypts to obtain the anonymous parameters RNi and RNx, the following operations are performed: S231. The roadside unit RSUj of the node retrieves the transaction data {ANC, AC, Signt} in the blockchain according to the anonymous ANC of the vehicle, and uses the public key of the quantum encryption service platform to verify the quantum encryption service platform signature value Signt to verify the correct integrity of ANC and AC stored in the blockchain. S232. The roadside unit RSUj of the node calculates the check code AC using RNi and RNx, and determines whether the calculated check code AC is equal to the check code AC in the transaction data. If not, the vehicle identity is illegal; if so, the vehicle identity is legal. The roadside unit RSUj of the node uploads the data {ANC, permit, Signj} to the blockchain and generates a blockchain index BI. Among them, permit is the vehicle-road collaborative permission information of the vehicle; Signj is the signature value generated by signing ANC and permit using the private key of the roadside unit RSUj of the node. S233. The roadside unit RSUj of the node calculates the vehicle key CK according to RNi and RNx, encrypts the vehicle key CK using the pre-shared key SPj to generate an encrypted message m5, and the roadside unit RSUj of the node generates a message body M5, M5 = [ANC, permit, m5, Signj], and sends the message body M5 to all other roadside units within this section j. S24. After receiving the message body M5, other roadside units within section j use the public key of the roadside unit RSUj of the node to verify the signature value Signj, and decrypt the encrypted message m5 using the pre-shared key SPj to obtain the vehicle key CK; subsequently, the vehicle uses the vehicle key CK for vehicle-road communication within this section j.
6. The vehicle-road cooperation method based on blockchain according to claim 4, characterized in that The specific process of step S3 is as follows: S31. The vehicle broadcasts a departure request message within section j. After the roadside unit rj2 closest to the vehicle in this section j receives the departure request message, it determines whether the roadside unit rj2 is the roadside unit RSUj of the node in this section j. If so, it enters step S32; if not, the roadside unit rj2 first encrypts the departure request message using the pre-shared key SPj and sends it to the roadside unit RSUj of the node, and enters step S32. S32. After receiving the vehicle's departure request message, the roadside unit RSUj of the node in this section j generates a section key LK, generates a smart contract containing the section key LK, and obtains the address POS uniquely identifying the smart contract; encrypts the blockchain index BI, section key LK, address POS, and the current timestamp Ts7 using the vehicle key CK to obtain an encrypted message m7, m7 = CK(BI, LK, POS, Ts7), the roadside unit RSUj of the node uses the private key of the roadside unit RSUj of the node to sign the encrypted message m7 to generate a signature value S7, the roadside unit RSUj of the node generates a message body M7, M7 = [ANC, m7, S7, Ts7], and the roadside unit RSUj of the node sends the message body M7 to the vehicle. In S33, after the vehicle receives the message body M7, it verifies the message body M7, including: judging the message validity through the timestamp Ts7 in the message body M7, and verifying the signature value S7 in the message body M7 with the public key of the roadside device RSUj of the node; after the verification of the message body M7 is successful, the vehicle decrypts the encrypted message m7 with the vehicle key CK to obtain the blockchain index BI, the key LK, and the address POS.
7. A vehicle-road cooperation method based on blockchain according to claim 6, characterized in that After step S33, the following specific process is further included: In S34, after the vehicle enters the next road section, i.e., road section k, it receives the digital certificate of the roadside device rk1 closest to the vehicle in road section k through broadcast and obtains the public key of this roadside device rk1; The vehicle encrypts the blockchain index BI and the address POS with the public key of this roadside device rk1 to obtain the encrypted message m8. The vehicle combines the anonymous ANC, the encrypted message m8, and the authentication request AddReq to generate the message body M8, M8 = [AddReq, ANC, m8]; the vehicle sends the message body M8 to this roadside device rk1 through broadcast; In S35, after this roadside device rk1 receives the authentication request message, i.e., the message body M8, it obtains the anonymous ANC and the encrypted message m8 of the vehicle, and decrypts the encrypted message m8 with the private key of the roadside device rk1 to obtain the blockchain index BI and the address POS; Judge whether this roadside device rk1 is the roadside device RSUk of the node of this road section k. If so, enter step S36; if not, this roadside device rk1 first encrypts the blockchain index BI and the address POS with the pre-set shared key SPk in road section k to obtain the encrypted message m9, m9 = SPk(BI, POS), and then combines the anonymous ANC, the encrypted message m9, and the authentication request AddReqk of the vehicle to generate the message body M9, M9 = [AddReq, ANC, m9]. This roadside device rk1 sends the message body M9 to the roadside device RSUk of the node of this road section k and enters step S36; In S36, after the roadside device RSUk of the node of this road section k obtains the anonymous ANC of the vehicle and decrypts to obtain the blockchain index BI and the address POS, the following operations are performed: In S361, the roadside device RSUk of the node retrieves in the blockchain according to the blockchain index BI, and retrieves the transaction data {ANC, permit, Signj} of the roadside device RSUj of the previous road section, i.e., road section j, for the vehicle identity verification, and verifies the signature value Signj with the public key of the roadside device RSUj of the node; In S362, find the smart contract through the address POS, and upload the transaction data {ANC, permit, Signj} to the blockchain to trigger the smart contract, and the smart contract returns the road section key LK to the roadside device RSUk of the node; In S363, the roadside device RSUk of the node sends the vehicle-road collaborative permission information and the road section key LK of this vehicle to all other roadside devices in this road section k; In S37, the vehicle performs vehicle-road communication within this road section k using the road section key LK.
8. A vehicle-road cooperation method based on blockchain according to claim 1, characterized in that, In step S1, during the vehicle identity registration process, the quantum encryption service platform also defines the validity period of the vehicle identity registration and uploads the validity period to the blockchain as well.
9. The vehicle-road collaborative method based on blockchain according to claim 8, wherein, In step S2, during the process of verifying the legitimacy of the vehicle identity, the node roadside device RSUj also retrieves the validity period of the vehicle identity registration from the blockchain and determines whether it has exceeded the validity period.
10. A vehicle-road collaborative system based on blockchain, characterized in that, Applied to a vehicle-road collaborative method based on blockchain according to any one of the above claims 1-8, the system includes: a quantum encryption service platform, a road section, a vehicle, and a blockchain; The quantum encryption service platform is responsible for issuing and managing digital certificates, generating vehicle anonymity and registering vehicle identities in the blockchain, and for managing the blockchain; The road section includes multiple roadside devices for verifying vehicle identities and vehicle-road collaboration; the node roadside devices in the road section are used to create transactions and deploy smart contracts on the blockchain.
Citation Information
Patent Citations
Vehicle identity authentication method based on twin block chain under scene of Internet of Vehicles
CN113965398A
VANET-oriented anonymous authentication method based on block chain
CN115442048A