A lightweight cross-domain identity authentication method and system in a connected vehicle environment

By providing a lightweight cross-domain identity authentication method in the Internet of Vehicles environment, the registration and authentication of trusted institutions and vehicles and roadside units is solved, and seamless switching authentication and efficient communication security are achieved.

CN119364359BActive Publication Date: 2025-05-13NANJING UNIV OF INFORMATION SCI & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411965524.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-13
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

In the Internet of Vehicles environment, when vehicles move across the domain, information exchange faces huge challenges, and the existing technology lacks an effective cross-domain vehicle communication security authentication solution, which is vulnerable to the risk of attackers intercepting, tampering and eavesdropping.

Method used

A lightweight cross-domain identity authentication method is provided, which establishes a first communication key by initializing parameters and registration of vehicles and roadside units by trusted institutions, and when the vehicle crosses the domain, it uses the first communication key to send a cross-domain notification. The second roadside unit determines whether it is the first communication, acquires or reads the authentication parameters of the vehicle, and conducts mutual authentication to establish a second communication key.

Benefits of technology

It realizes seamless switching authentication between cross-domain vehicles and roadside units, reduces attack risks, improves communication security, and reduces the time overhead of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119364359B_ABST
    Figure CN119364359B_ABST
Patent Text Reader

Abstract

The present invention discloses a lightweight cross-domain identity authentication method and system in a vehicle networking environment, the method comprising: a vehicle and each roadside unit register with a trusted institution; the vehicle and the first roadside unit mutually authenticate to establish a first communication key; the vehicle to be cross-domain sends a cross-domain notification to the first roadside unit using the first communication key, and the first roadside unit sends the cross-domain notification to the second roadside unit; the second roadside unit determines whether it is the first time to communicate with the vehicle to be cross-domain based on the cross-domain notification; if so, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain; if not, the second roadside unit reads the authentication parameters of the vehicle to be cross-domain; the vehicle to be cross-domain drives to the domain of the second roadside unit, and the vehicle to be cross-domain and the second roadside unit mutually authenticate to establish a second communication key based on the authentication parameters. The present invention can ensure seamless switching authentication between cross-domain vehicles and roadside units.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a lightweight cross-domain identity authentication method and system in a vehicle networking environment, and belongs to the technical field of information encryption. Background Art

[0002] With the continuous development and popularization of the Internet of Things (IoT), the concept of Internet of Vehicles (IoV) has emerged. In an IoV environment, data exchange between vehicles and infrastructure can provide road condition information and real-time navigation to enhance driving safety.

[0003] Since vehicles are mobile entities that move across different domains, they need to communicate with roadside units (RSUs) in different areas. When vehicles move from one domain to another, information exchange faces huge challenges. The on-board unit (OBU) installed on the vehicle plays a vital role in exchanging information with the roadside units deployed on both sides of the road. The roadside unit transmits data collected from nearby traffic lights to passing vehicles, providing instructions to adjust the speed of the vehicle while driving. This information exchange enables vehicles to identify high-risk situations in a timely manner and automatically take necessary measures.

[0004] Seamless services in the Internet of Vehicles are essential to facilitate cross-regional driving of vehicles. The openness of the Internet of Vehicles environment makes data transmitted on public channels vulnerable to interception, tampering, and eavesdropping by attackers. Attackers can maliciously impersonate legitimate vehicles, and this vulnerability can affect the communication security between vehicles and roadside units, and may even endanger the privacy of users and vehicles. Therefore, it is imperative to ensure the communication security between vehicles and roadside units in the Internet of Vehicles environment. To address this issue, researchers have proposed various authentication and key agreement (AKA) protocols to enhance the security of communications between vehicles and roadside units. Currently, there is a lack of authentication schemes to ensure the security of cross-domain vehicle communications. Summary of the invention

[0005] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a lightweight cross-domain identity authentication method and system in a vehicle networking environment, which can ensure seamless switching authentication between cross-domain vehicles and roadside units. To achieve the above purpose, the present invention is implemented by adopting the following technical solutions:

[0006] In a first aspect, the present invention provides a lightweight cross-domain identity authentication method in a vehicle networking environment, comprising:

[0007] The trusted institution initializes parameters, and the vehicle and each roadside unit register with the trusted institution;

[0008] The vehicle and the first roadside unit perform mutual authentication using a trusted authority to establish a first communication key;

[0009] When the vehicle to be crossed uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit;

[0010] The second roadside unit determines whether it is the first communication with the vehicle to be cross-domain based on the cross-domain notification; if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted institution; if it is not the first communication, the second roadside unit reads the stored authentication parameters of the vehicle to be cross-domain;

[0011] In response to the vehicle to cross the domain driving into the domain of the second roadside unit, the vehicle to cross the domain and the second roadside unit perform mutual authentication based on the authentication parameters to establish a second communication key.

[0012] In combination with the first aspect, optionally, the trusted institution initialization parameter includes:

[0013] The trusted authority selects a one-way collision-resistant hash function, expressed as ;

[0014] Generate a master key using a random number generator .

[0015] In combination with the first aspect, optionally, Vehicles There is a unique private key when it leaves the factory and long ID ,vehicle In a trusted institution Registration, including:

[0016] vehicle Select a random number of vehicles ,calculate ,in For vehicles The false identity, Trusted institution The selected one-way collision-resistant hash function, It is a concatenation operation that directly connects the binary numbers of two parameters end to end; vehicle Through the safe passage Send to a trusted institution ;

[0017] Trusted Institutions Receive vehicle Sent After that, for the received Select random number As a parameter of the temporary identity, calculate and ,in For vehicles Temporary status, For vehicles Authentication credentials, Master key; trusted authority storage and will Send to vehicle ;

[0018] vehicle Received from a trusted institution Sent After that, calculate , , and ,in, To randomize the vehicle Encrypted ciphertext, For the general Encrypted ciphertext, is the vehicle information summary, To change the long ID Encrypted ciphertext, is a binary XOR operation; vehicle storage , the vehicle is registered with a trusted institution.

[0019] In combination with the first aspect, optionally, each roadside unit is pre-assigned with a long identity code , each roadside unit is in a trusted institution Registration, including:

[0020] Roadside Unit Long ID code through secure channel Send to a trusted institution ;

[0021] Trusted Institutions Received roadside unit Sent After that, for the received Select random number As a parameter for generating pseudo-identity, calculate , and ,in, Roadside Unit Authentication credentials, Roadside Unit The false identity, To change the long ID Encrypted ciphertext; trusted authority storage and will Send to roadside unit ;

[0022] Roadside Unit Received from a trusted institution Sent After that, store , the roadside unit is registered with the trusted agency.

[0023] In combination with the first aspect, optionally, the vehicle and the first roadside unit use a trusted institution to perform mutual authentication to establish a first communication key, including:

[0024] vehicle calculate , and , and check ,in, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the vehicle Log in to the system with a registered identity; vehicle choose and ,calculate and ,in is a temporary random number, To convert a temporary random number Encrypted ciphertext, A summary of the first communication for the vehicle, For vehicles To the first roadside unit Timestamp of sending information; vehicle Through the public channel Send to first roadside unit ;

[0025] First roadside unit receive Post-inspection ; In response to The first roadside unit choose and ,calculate and ,in, is a temporary random number, To convert a temporary random number Encrypted ciphertext, a first communication digest for a first roadside unit, First roadside unit Trusted Institutions Timestamp of when the message was sent, First roadside unit The long ID code, First roadside unit The false identity, First roadside unit Authentication credentials for the first roadside unit Will Send to a trusted institution ;

[0026] Trusted Institutions receive Post-inspection ; In response to The preset second time threshold is not exceeded, and the trusted institution According to vehicle Fake identity Find the vehicle from storage Temporary status ,calculate , )and , and check ,in The first communication digest of the vehicle calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify vehicle Verification successful;

[0027] Trusted Institutions According to the first roadside unit Pseudo long ID code Find from storage ,calculate , , and , and check ,in, To place the first roadside unit Long ID code Encrypted ciphertext, The first communication digest of the first roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify first roadside unit Verification successful;

[0028] Trusted Institutions choose ,calculate , and ,in, Trusted institution To the first roadside unit Timestamp of when the message was sent, For encryption The ciphertext, For encryption The ciphertext, A first communication digest for a trusted authority; a trusted authority Will Send to first roadside unit ;

[0029] First roadside unit receive Post-inspection ; In response to The preset third time threshold is not exceeded, and the first roadside unit calculate , and check ,in A first communication digest of a trusted institution calculated for a first roadside unit; in response to both sides of the equation being equal, the first roadside unit Verify trusted institutions Verification successful;

[0030] First roadside unit calculate and ,in, is the first communication key; the first roadside unit choose ,calculate ,in First roadside unit The timestamp of sending the message to vehicle 𝑉𝑖, A second communication digest for a trusted authority; a first roadside unit Will Send to vehicle ;

[0031] vehicle receive Post-inspection ; In response to The vehicle does not exceed the preset fourth time threshold. calculate , and , and verify ,in A second communication digest of the trusted authority calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify trusted institutions The verification is successful, and the first communication key established by the vehicle and the first roadside unit using a trusted institution for mutual authentication is obtained. .

[0032] In combination with the first aspect, optionally, when the vehicle to be cross-domain sends a cross-domain notification to the first roadside unit using the first communication key, the first roadside unit sends the cross-domain notification to the second roadside unit, including:

[0033] First roadside unit Generate notification and select ,calculate , ,in, First roadside unit The long ID code, For use As the ciphertext encrypted with the symmetric key, For use As a symmetric encryption function of a symmetric key, Second roadside unit The false identity, For vehicles The false identity, To connect the binary numbers of two parameters directly end to end, a second communication summary for the first roadside unit, Trusted institution The selected one-way collision-resistant hash function, First roadside unit Authentication credentials, First roadside unit Trusted Institutions Timestamp of sending information; first roadside unit Will Send to a trusted institution ;

[0034] Trusted Institutions receive Post-inspection ; In response to If the preset fifth time threshold is not exceeded, the first roadside unit is continued. Authentication of identity; trusted authority According to the first roadside unit Fake identity Get Encrypted ciphertext ,calculate , and , and check ,in is a binary XOR operation, is the master key, a second communication digest of the first roadside unit calculated by the trusted authority, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the trusted institution Verify first roadside unit Verification successful;

[0035] Trusted Institutions choose ,calculate ,in For use Symmetric decryption function as a symmetric key; trusted authority According to the second roadside unit Fake identity Get the second roadside unit Long ID code Encrypted ciphertext ,calculate , and ,in Second roadside unit The long ID code, Second roadside unit Authentication credentials, A third communication summary for the first roadside unit, Trusted institution To the second roadside unit Timestamp of sent information; trusted institution Will Send to second roadside unit ;

[0036] Second roadside unit receive After that, check ; In response to The preset sixth time threshold is not exceeded, and the second roadside unit calculate , and check ,in The third communication digest of the first roadside unit calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the first roadside unit legitimacy and received cross-domain notification.

[0037] In combination with the first aspect, optionally, if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted institution, including:

[0038] Second roadside unit Generate data request And select the second roadside unit random number and ,calculate and ,in To convert random numbers Encrypted ciphertext, a first communication digest for a second roadside unit, For the second roadside unit, Timestamp of sending information; Second roadside unit send To a trusted institution ;

[0039] Trusted Institutions receive After that, check ; In response to The preset seventh time threshold has not been exceeded, and the trusted institution calculate and , and check ,in The first communication digest of the second roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution verifies Second roadside unit Verification successful;

[0040] Trusted Institutions According to vehicle Pseudo-identity Get the vehicle Temporary status ,calculate and ,in, For vehicles Authentication credentials, To use a symmetric encryption algorithm Encrypted ciphertext, For Encryption function for symmetric keys; trusted authority choose ,calculate ,in A second communication summary for the vehicle, Trusted institution Timestamp of information sent to the second roadside unit; sent by a trusted authority To the second roadside unit ;

[0041] Second roadside unit receive After that, check ; In response to The preset eighth time threshold is not exceeded, and the second roadside unit calculate and , and check ,in, For is the decryption function of the symmetric key, A second communication digest of the vehicle calculated for the second roadside unit, in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle The legality of calculation ,in For vehicle information Encrypted ciphertext; Second roadside unit Storage Vehicles Authentication parameters { , }.

[0042] In combination with the first aspect, optionally, in response to the vehicle to be cross-domain driving into the domain of the second roadside unit, the vehicle to be cross-domain and the second roadside unit perform mutual authentication based on the authentication parameter to establish a second communication key, including:

[0043] vehicle choose and ,calculate , ,in The random number generated for this communication, To convert random numbers Encrypted ciphertext, The third communication summary for the vehicle, For vehicles To the second roadside unit Timestamp of sending information; vehicle Will Send to second roadside unit ;

[0044] Second roadside unit receive After that, check ; In response to The preset ninth time threshold is not exceeded, and the second roadside unit According to the vehicle Pseudo-identity Get vehicle information Encrypted ciphertext ,calculate , and , and check ,in The third information summary of the vehicle calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle the legality of

[0045] Second roadside unit choose and ,calculate , and ,in For Encrypted ciphertext, To generate a session key for the second RSU The random number selected, a second communication digest for a second roadside unit, Communication key for the second roadside unit Will Send to vehicle ;

[0046] vehicle receive Post-inspection ; In response to The vehicle count , and , and check ,in A second communication digest of a second roadside unit calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify Second Roadside Unit The verification is successful, and the second communication key established by the vehicle and the second roadside unit for mutual authentication based on the authentication parameters is obtained. .

[0047] In a second aspect, the present invention provides a system including a trusted institution, a plurality of vehicles and a plurality of roadside units.

[0048] The trusted institution is in communication connection with a plurality of vehicles and a plurality of roadside units, and is used to provide registration and authentication for the vehicles and the roadside units;

[0049] The roadside unit is connected in communication with a trusted institution to collect road condition information and regularly upload the collected road condition information to the trusted institution; the roadside unit is connected in communication with a vehicle to guide safe driving of the vehicle through data interaction.

[0050] In combination with the second aspect, optionally, the vehicle is configured with an OBU and an SGX1; the OBU is used to store general data; the SGX1 is used to store secret data; the roadside unit is configured with a TPD and SGX2; the TPD is used to store general data; the SGX2 is used to store secret data; and the trusted institution is configured with a database for storing data.

[0051] Compared with the prior art, the lightweight cross-domain identity authentication method and system in a connected vehicle environment provided by the embodiment of the present invention have the following beneficial effects:

[0052] The vehicle and the first roadside unit of the present invention use a trusted institution to perform mutual authentication to establish a first communication key; the present invention provides intra-domain authentication, and mutual authentication is performed between communication entities, so that both the vehicle and the first roadside unit provide identity authentication credentials to confirm the legitimacy of their identities;

[0053] When the vehicle to be crossed by the present invention uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit; the second roadside unit determines whether it is the first time to communicate with the vehicle to be crossed based on the cross-domain notification; if it is the first time to communicate, the second roadside unit obtains the authentication parameters of the vehicle to be crossed from a trusted institution; if it is not the first time to communicate, the second roadside unit reads the stored authentication parameters of the vehicle to be crossed; the second roadside unit of the present invention can determine whether it is the first time for the vehicle to communicate with itself, and can ensure seamless switching authentication;

[0054] In response to a vehicle to be crossed traveling to a domain of a second roadside unit, the vehicle to be crossed and the second roadside unit perform mutual authentication based on authentication parameters to establish a second communication key; when the vehicle crosses the domain, the vehicle and the second roadside unit can directly authenticate each other without the participation of a trusted institution, thereby reducing a large amount of time overhead compared to a simple method of repeated single-domain authentication; the present invention adopts all symmetric encryption methods, and the communication overhead is small;

[0055] The vehicle and each roadside unit of the present invention use a long identity code to register with a trusted institution. Since the long identity code has a long bit length and a high entropy value, an attacker cannot correctly guess and verify the vehicle and each roadside unit within the probabilistic polynomial time. During the registration stage, the trusted institution stores the pseudo-identity of the vehicle and the roadside unit through a hash operation, which is more secure than the traditional registration that directly stores the real identity information of the vehicle and can resist theft attacks by internal personnel. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 It is a flowchart of a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0057] Figure 2 It is a schematic diagram of a vehicle registering with a trusted institution in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0058] Figure 3 It is a schematic diagram of each roadside unit registering with a trusted institution in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0059] Figure 4 It is a schematic diagram of mutual authentication between a vehicle and a first roadside unit in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0060] Figure 5 It is a schematic diagram of a first roadside unit sending a cross-domain notification to a second roadside unit in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0061] Figure 6 It is a schematic diagram of a second roadside unit acquiring authentication parameters of a vehicle to be cross-domain from a trusted institution in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Embodiment 1 of the present invention;

[0062] Figure 7 It is a schematic diagram of mutual authentication between a vehicle to be crossed and a second roadside unit in a lightweight cross-domain identity authentication method in a vehicle networking environment provided by Example 1 of the present invention. DETAILED DESCRIPTION

[0063] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.

[0064] Example 1

[0065] like Figure 1 As shown, an embodiment of the present invention provides a lightweight cross-domain identity authentication method in a vehicle networking environment, including:

[0066] The trusted institution initializes parameters, and the vehicle and each roadside unit register with the trusted institution;

[0067] The vehicle and the first roadside unit perform mutual authentication using a trusted authority to establish a first communication key;

[0068] When the vehicle to be crossed uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit;

[0069] The second roadside unit determines whether it is the first communication with the vehicle to be cross-domain based on the cross-domain notification; if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted institution; if it is not the first communication, the second roadside unit reads the stored authentication parameters of the vehicle to be cross-domain;

[0070] In response to the vehicle to cross the domain driving into the domain of the second roadside unit, the vehicle to cross the domain and the second roadside unit perform mutual authentication based on the authentication parameters to establish a second communication key.

[0071] The specific steps include:

[0072] Step 1: The trusted authority initializes parameters.

[0073] The trusted authority selects a one-way collision-resistant hash function, expressed as ; Generate a master key using a random number generator .

[0074] Step 2: The vehicle and each roadside unit are registered with a trusted authority.

[0075] Step 2.1: The vehicle is registered with a trusted authority.

[0076] When a car manufacturer produces a vehicle, each vehicle Have a unique private key and long ID .

[0077] like Figure 2 As shown, the vehicle Trusted Institutions Registration, including:

[0078] Step 2.1.1: Vehicle Select a random number of vehicles ,calculate ,in For vehicles The false identity, Trusted institution The selected one-way collision-resistant hash function, It is a concatenation operation that directly connects the binary numbers of the two parameters end to end.

[0079] vehicle Through the safe passage Send to a trusted institution .

[0080] Step 2.1.2: Trusted Institutions Receive vehicle Sent After that, for the received Select random number As a parameter of the temporary identity, calculate and ,in For vehicles Temporary status, For vehicles Authentication credentials, The primary key.

[0081] Trusted Institutions storage and will Send to vehicle .

[0082] Step 2.1.3: Vehicle Received from a trusted institution Sent After that, calculate , , and ,in, To randomize the vehicle Encrypted ciphertext, For the general Encrypted ciphertext, is the vehicle information summary, To change the long ID Encrypted ciphertext, is a binary XOR operation; vehicle storage , the vehicle is registered with a trusted institution.

[0083] Step 2.2: Each roadside unit registers with a trusted institution.

[0084] Each roadside unit is pre-assigned a long identity code .

[0085] like Figure 3 As shown, each roadside unit is registered with a trusted institution, including:

[0086] Step 2.2.1: Roadside Unit Long ID code through secure channel Send to a trusted institution .

[0087] Step 2.2.2: Trusted Institutions Received roadside unit Sent After that, for the received Select random number As a parameter for generating pseudo-identity, calculate , and ,in, Roadside Unit Authentication credentials, Roadside Unit The false identity, To change the long ID Encrypted ciphertext.

[0088] Trusted Institutions storage and will Send to roadside unit .

[0089] Step 2.2.3: Roadside Unit Received from a trusted institution Sent After that, store , the roadside unit is registered with the trusted agency.

[0090] In this embodiment, the vehicle and each roadside unit use a long identity code to register with a trusted institution. Since the long identity code has a long bit length and a high entropy value, an attacker cannot correctly guess and verify the vehicle and each roadside unit within a probabilistic polynomial time.

[0091] In the present embodiment, during the registration phase, the trusted institution stores the pseudo-identities of the vehicle and the roadside unit through hash operations, which is more secure than the traditional registration method of directly storing the real identity information of the vehicle and can resist theft attacks by internal personnel.

[0092] Step 3: The vehicle and the first roadside unit use a trusted authority to perform mutual authentication and establish a first communication key.

[0093] This step is an intra-domain authentication step. The vehicle and the first roadside unit need to be authenticated with the help of a trusted organization and establish a first communication key before the vehicle can communicate with the first roadside unit.

[0094] like Figure 4 As shown, the vehicle and the first roadside unit use a trusted institution to perform mutual authentication to establish a first communication key, including:

[0095] Step 3.1: Vehicle calculate , and , and check ,in, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the vehicle Log in to the system with a registered identity.

[0096] vehicle choose and ,calculate and ,in is a temporary random number, To convert a temporary random number Encrypted ciphertext, A summary of the first communication for the vehicle, For vehicles To the first roadside unit The timestamp of when the message was sent.

[0097] vehicle Through the public channel Send to first roadside unit .

[0098] Step 3.2: First Roadside Unit receive Post-inspection .

[0099] In response to The first roadside unit choose and ,calculate and ,in, is a temporary random number, To convert a temporary random number Encrypted ciphertext, a first communication digest for a first roadside unit, First roadside unit Trusted Institutions Timestamp of when the message was sent, First roadside unit The long ID code, First roadside unit The false identity, First roadside unit Authentication credentials.

[0100] First roadside unit Will Send to a trusted institution .

[0101] Step 3.3: Trusted Institutions receive Post-inspection .

[0102] In response to The preset second time threshold is not exceeded, and the trusted institution According to vehicle Fake identity Find the vehicle from storage Temporary status ,calculate , )and , and check ,in The first communication digest of the vehicle calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify vehicle Verification successful.

[0103] Step 3.4: Trusted Institutions According to the first roadside unit Pseudo long ID code Find from storage ,calculate , , and , and check ,in, To place the first roadside unit Long ID code Encrypted ciphertext, The first communication digest of the first roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify first roadside unit Verification successful.

[0104] Step 3.5: Trusted Institutions choose ,calculate , and ,in, Trusted institution To the first roadside unit Timestamp of when the message was sent, For encryption The ciphertext, For encryption The ciphertext, The first communication digest for the trusted authority.

[0105] Trusted Institutions Will Send to first roadside unit .

[0106] Step 3.6: First Roadside Unit receive Post-inspection .

[0107] In response to The preset third time threshold is not exceeded, and the first roadside unit calculate , and check ,in A first communication digest of a trusted institution calculated for a first roadside unit; in response to both sides of the equation being equal, the first roadside unit Verify trusted institutions Verification successful.

[0108] Step 3.7: First Roadside Unit calculate and ,in, is the first communication key; the first roadside unit choose ,calculate ,in First roadside unit The timestamp of sending the message to vehicle 𝑉𝑖, A second communication digest for a trusted authority.

[0109] First roadside unit Will Send to vehicle .

[0110] Step 3.8: Vehicle receive Post-inspection .

[0111] In response to The vehicle does not exceed the preset fourth time threshold. calculate , and , and verify ,in A second communication digest of the trusted authority calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify trusted institutions The verification is successful, and the first communication key established by the vehicle and the first roadside unit using a trusted institution for mutual authentication is obtained. .

[0112] Step 4: When the vehicle to cross the domain uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit.

[0113] This step is a cross-domain notification step, in which the first roadside unit notifies the second roadside unit that the vehicle to be cross-domain is about to arrive at the domain sent to the second roadside unit.

[0114] like Figure 5 As shown, the specific steps of the first roadside unit sending the cross-domain notification to the second roadside unit include:

[0115] Step 4.1: First Roadside Unit Generate notification and select ,calculate , ,in, First roadside unit The long ID code, For use As the ciphertext encrypted with the symmetric key, For use As a symmetric encryption function of a symmetric key, Second roadside unit The false identity, For vehicles The false identity, To connect the binary numbers of two parameters directly end to end, a second communication summary for the first roadside unit, Trusted institution The selected one-way collision-resistant hash function, First roadside unit Authentication credentials, First roadside unit Trusted Institutions The timestamp of when the message was sent.

[0116] First roadside unit Will Send to a trusted institution .

[0117] Step 4.2: Trusted Institutions receive Post-inspection .

[0118] In response to If the preset fifth time threshold is not exceeded, the first roadside unit is continued. Authentication of trusted institutions According to the first roadside unit Fake identity Get Encrypted ciphertext ,calculate , and , and check ,in is a binary XOR operation, is the master key, a second communication digest of the first roadside unit calculated by the trusted authority, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the trusted institution Verify first roadside unit Verification successful.

[0119] Step 4.3: Trusted Institutions choose ,calculate ,in For use Symmetric decryption function as a symmetric key; trusted authority According to the second roadside unit Fake identity Get the second roadside unit Long ID code Encrypted ciphertext ,calculate , and ,in Second roadside unit The long ID code, Second roadside unit Authentication credentials, A third communication summary for the first roadside unit, Trusted institution To the second roadside unit The timestamp of when the message was sent.

[0120] Trusted Institutions Will Send to second roadside unit .

[0121] Step 4.4: Second Roadside Unit receive After that, check .

[0122] In response to The preset sixth time threshold is not exceeded, and the second roadside unit calculate , and check ,in The third communication digest of the first roadside unit calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the first roadside unit legitimacy and received cross-domain notification.

[0123] Step 5: The second roadside unit determines whether it is the first communication with the vehicle to be cross-domain based on the cross-domain notification; if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from a trusted agency; if it is not the first communication, the second roadside unit reads the stored authentication parameters of the vehicle to be cross-domain.

[0124] Among them, if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted organization, and this step is a data request step.

[0125] like Figure 6 As shown, the specific steps for the second roadside unit to obtain the authentication parameters of the vehicle to be crossed from the trusted institution include:

[0126] Step 5.1: Second Roadside Unit Generate data request And select the second roadside unit random number and ,calculate and ,in To convert random numbers Encrypted ciphertext, a first communication digest for a second roadside unit, For the second roadside unit, The timestamp of when the message was sent.

[0127] Second roadside unit send To a trusted institution .

[0128] Step 5.2: Trusted Institutions receive After that, check .

[0129] In response to The preset seventh time threshold has not been exceeded, and the trusted institution calculate and , and check ,in The first communication digest of the second roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution verifies Second roadside unit Verification successful.

[0130] Step 5.3: Trusted Institutions According to vehicle Fake identity Get the vehicle Temporary status ,calculate and ,in, For vehicles Authentication credentials, To use a symmetric encryption algorithm Encrypted ciphertext, For A symmetric key encryption function.

[0131] Trusted Institutions choose ,calculate ,in A second communication summary for the vehicle, Trusted institution The timestamp of when the information was sent to the second roadside unit.

[0132] Sent by a trusted organization To the second roadside unit .

[0133] Step 5.4: Second Roadside Unit receive After that, check .

[0134] In response to The preset eighth time threshold is not exceeded, and the second roadside unit calculate and , and check ,in, For is the decryption function of the symmetric key, A second communication digest of the vehicle calculated for the second roadside unit, in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle the legitimacy of.

[0135] calculate ,in For vehicle information Encrypted ciphertext; Second roadside unit Storage Vehicles Authentication parameters { , }.

[0136] In this embodiment, the second roadside unit can determine whether it is the first time for the vehicle to communicate with itself, and can ensure seamless switching authentication.

[0137] Step 6: In response to the vehicle to be cross-domain driving into the domain of the second roadside unit, the vehicle to be cross-domain and the second roadside unit perform mutual authentication based on the authentication parameters to establish a second communication key.

[0138] This step is a cross-domain authentication step. When the vehicle to be crossed travels to the domain of the second roadside unit and wishes to obtain road data collected by the domain of the second roadside unit, the vehicle to be crossed and the second roadside unit perform mutual authentication and establish a second communication key.

[0139] like Figure 7 As shown, the specific steps for mutual authentication between the vehicle to be cross-domain and the second roadside unit include:

[0140] Step 6.1: Vehicle choose and ,calculate , ,in The random number generated for this communication, To convert random numbers Encrypted ciphertext, The third communication summary for the vehicle, For vehicles To the second roadside unit The timestamp of when the message was sent.

[0141] vehicle Will Send to second roadside unit .

[0142] Step 6.2: Second Roadside Unit receive After that, check .

[0143] In response to The preset ninth time threshold is not exceeded, and the second roadside unit According to the vehicle Pseudo-identity Get vehicle information Encrypted ciphertext ,calculate , and , and check ,in The third information summary of the vehicle calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle the legitimacy of.

[0144] Step 6.3: Second Roadside Unit choose and ,calculate , and ,in For Encrypted ciphertext, To generate a session key for the second RSU The random number selected, a second communication digest for a second roadside unit, For the second communication key.

[0145] Second roadside unit Will Send to vehicle .

[0146] Step 6.4: Vehicle receive Post-inspection .

[0147] In response to The vehicle count , and , and check ,in A second communication digest of a second roadside unit calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify Second Roadside Unit The verification is successful, and the second communication key established by the vehicle and the second roadside unit for mutual authentication based on the authentication parameters is obtained. .

[0148] In this embodiment, when the vehicle crosses domains, the vehicle and the second roadside unit can directly authenticate each other without the participation of a trusted organization, which reduces a lot of time overhead compared to the simple method of repeated single-domain authentication. The present invention adopts symmetric encryption methods throughout, and the communication overhead is relatively small.

[0149] The vehicle and each roadside unit of the present invention use a long identity code to register with a trusted institution. Since the long identity code has a long bit length and a high entropy value, an attacker cannot correctly guess and verify the vehicle and each roadside unit within the probabilistic polynomial time. During the registration stage, the trusted institution stores the pseudo-identity of the vehicle and the roadside unit through a hash operation, which is more secure than the traditional registration that directly stores the real identity information of the vehicle and can resist theft attacks by internal personnel.

[0150] This embodiment achieves the following safety goals while being lightweight:

[0151] Capture attack resistance: Even if an attacker captures a legitimate entity (vehicle and / or roadside unit), the attacker cannot easily obtain the data stored in the entity database to calculate the session key;

[0152] Resisting Offline Identity Guessing Attacks: Since the long-term identities of vehicles and roadside units have long bit lengths and high entropy values, attackers cannot correctly guess and verify these identities in probabilistic polynomial time;

[0153] Resisting Man-in-the-Middle (MITM Attacks): This embodiment can prevent an attacker from intercepting and tampering with messages exchanged through a public channel between two communicating entities, thereby preventing the attacker from establishing communication with both parties;

[0154] Resisting Impersonation Attacks: Attackers attempt to impersonate legitimate entities (vehicles and / or roadside units) to send messages to other entities. This embodiment can ensure that the receiver can verify the authenticity of the message and prevent the attacker from being authenticated.

[0155] Mutual Authentication: This embodiment requires both parties to provide authentication credentials to each other during the communication process to confirm the legitimacy of each other's identities;

[0156] Anonymity: During the entire authentication and key agreement (AKA) process, the entity needs to remain anonymous to ensure that the real identity and other sensitive information are not disclosed;

[0157] Untraceability: The identity or activity of the vehicle cannot be tracked or identified during the communication process;

[0158] Perfect Forward Secrecy (PFS): Even if an attacker obtains the current session key, the attacker cannot access the entity's previous session keys.

[0159] Example 2

[0160] An embodiment of the present invention provides a lightweight cross-domain identity authentication system in a vehicle networking environment, including a trusted organization, multiple vehicles, and multiple roadside units.

[0161] The trusted institution is connected in communication with multiple vehicles and multiple roadside units to provide registration and authentication for the vehicles and roadside units.

[0162] The roadside unit is connected to the trusted institution for collecting road condition information and regularly uploading the collected road condition information to the trusted institution. The roadside unit is connected to the vehicle for guiding the vehicle to drive safely through data interaction.

[0163] The vehicle is a semi-trusted device, equipped with OBU and SGX1; OBU is used to store general data; SGX1 is used to store secret data.

[0164] The roadside unit is a semi-trusted device, which is equipped with TPD and SGX2. TPD is used to store general data, while SGX2 is used to store secret data.

[0165] The trusted institution is provided with a database for storing data.

[0166] In this embodiment, when a vehicle is registered with a trusted institution, each vehicle Unique private key Stored in SGX1, the trusted institution CS will Stored in the database, the vehicle will Stored in the OBU. Each roadside unit is registered with a trusted institution, and each roadside unit is pre-assigned a long identity code Stored in SGX2, trusted institution Will The second roadside unit sends the vehicle's authentication parameters { , }stored in TPD.

[0167] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A lightweight cross-domain identity authentication method in a vehicle networking environment, characterized in that: include: The trusted institution initializes parameters, and the vehicle and each roadside unit register with the trusted institution; The vehicle and the first roadside unit perform mutual authentication using a trusted authority to establish a first communication key; When the vehicle to be crossed uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit; When the vehicle to be crossed uses the first communication key to send a cross-domain notification to the first roadside unit to cross to the second roadside unit, the first roadside unit sends the cross-domain notification to the second roadside unit, including: First roadside unit Generate notification and select ,calculate , ,in, First roadside unit The long ID code, For use As the ciphertext encrypted with the symmetric key, For use As a symmetric encryption function of a symmetric key, Second roadside unit The false identity, For vehicles The false identity, To connect the binary numbers of two parameters directly end to end, a second communication summary for the first roadside unit, Trusted institution The selected one-way collision-resistant hash function, First roadside unit Authentication credentials, First roadside unit Trusted Institutions Timestamp of sending information; first roadside unit Will Send to a trusted institution ; Trusted Institutions receive Post-inspection ; In response to If the preset fifth time threshold is not exceeded, the first roadside unit is continued. Authentication of identity; trusted authority According to the first roadside unit Pseudo-identity Get Encrypted ciphertext ,calculate , and , and check ,in is a binary XOR operation, is the master key, a second communication digest of the first roadside unit calculated by the trusted authority, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the trusted institution Verify first roadside unit Verification successful; Trusted Institutions choose ,calculate ,in For use Symmetric decryption function as a symmetric key; trusted authority According to the second roadside unit Pseudo-identity Get the second roadside unit Long ID code Encrypted ciphertext ,calculate , and ,in Second roadside unit The long ID code, Second roadside unit Authentication credentials, A third communication summary for the first roadside unit, Trusted institution To the second roadside unit Timestamp of sending information; trusted institution Will Send to second roadside unit ; Second roadside unit receive After that, check ; In response to The preset sixth time threshold is not exceeded, and the second roadside unit calculate , and check ,in The third communication digest of the first roadside unit calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the first roadside unit The legitimacy of and received cross-domain notification; The second roadside unit determines whether it is the first communication with the vehicle to be cross-domain based on the cross-domain notification; if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted institution; if it is not the first communication, the second roadside unit reads the stored authentication parameters of the vehicle to be cross-domain; Wherein, if it is the first communication, the second roadside unit obtains the authentication parameters of the vehicle to be cross-domain from the trusted institution, including: Second roadside unit Generate data request And select the second roadside unit random number and ,calculate and ,in To convert random numbers Encrypted ciphertext, a first communication digest for a second roadside unit, For the second roadside unit, Timestamp of sending information; Second roadside unit send To a trusted institution ; Trusted Institutions receive After that, check ; In response to The preset seventh time threshold has not been exceeded, and the trusted institution calculate and , and check ,in The first communication digest of the second roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify Second Roadside Unit Verification successful; Trusted Institutions According to vehicle Pseudo-identity Get the vehicle Temporary status ,calculate and ,in, For vehicles Authentication credentials, To use a symmetric encryption algorithm Encrypted ciphertext, For Encryption function for symmetric keys; trusted authority choose ,calculate ,in A second communication summary for the vehicle, Trusted institution Timestamp of information sent to the second roadside unit; sent by a trusted authority To the second roadside unit ; Second roadside unit receive After that, check ; In response to The preset eighth time threshold is not exceeded, and the second roadside unit calculate and , and check ,in, For is the decryption function of the symmetric key, A second communication digest of the vehicle calculated for the second roadside unit, in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle The legality of calculation ,in For vehicle information Encrypted ciphertext; second roadside unit Storage Vehicles Authentication parameters { , }; In response to the vehicle to cross the domain driving into the domain of the second roadside unit, the vehicle to cross the domain and the second roadside unit perform mutual authentication based on the authentication parameters to establish a second communication key.

2. The lightweight cross-domain identity authentication method in the vehicle networking environment according to claim 1 is characterized in that: The trusted institution initialization parameters include: The trusted authority selects a one-way collision-resistant hash function, expressed as ; Generate a master key using a random number generator .

3. The lightweight cross-domain identity authentication method in a vehicle networking environment according to claim 1 is characterized in that: No. Vehicles There is a unique private key when it leaves the factory and long ID ,vehicle In a trusted institution Registration, including: vehicle Select a random number of vehicles ,calculate ,in For vehicles The false identity, Trusted institution The selected one-way collision-resistant hash function, It is a concatenation operation that directly connects the binary numbers of two parameters end to end; vehicle Through the safe passage Send to a trusted institution ; Trusted Institutions Receive vehicle Sent After that, for the received Select random number As a parameter of the temporary identity, calculate and ,in For vehicles Temporary status, For vehicles Authentication credentials, Master key; trusted authority storage and will Send to vehicle ; vehicle Received from a trusted institution Sent After that, calculate , , and ,in, To randomize the vehicle Encrypted ciphertext, For the general Encrypted ciphertext, is the vehicle information summary, To change the long ID Encrypted ciphertext, is a binary XOR operation; vehicle storage , the vehicle is registered with a trusted institution.

4. The lightweight cross-domain identity authentication method in a vehicle networking environment according to claim 3 is characterized in that: Each roadside unit is pre-assigned a long identity code , each roadside unit is in a trusted institution Registration, including: Roadside Unit Long ID code through secure channel Send to a trusted institution ; Trusted Institutions Received roadside unit Sent After that, for the received Select random number As a parameter for generating pseudo-identity, calculate , and ,in, Roadside Unit Authentication credentials, Roadside Unit The false identity, To change the long ID Encrypted ciphertext; trusted authority storage and will Send to roadside unit ; Roadside Unit Received from a trusted institution Sent After that, store , the roadside unit is registered with the trusted agency.

5. The lightweight cross-domain identity authentication method in a vehicle networking environment according to claim 4 is characterized in that: The vehicle and the first roadside unit use a trusted institution to perform mutual authentication to establish a first communication key, including: vehicle calculate , and , and check ,in, To determine whether both sides of the equation are equal; in response to the equality of both sides of the equation, the vehicle Log in to the system with a registered identity; vehicle choose and ,calculate and ,in is a temporary random number, To convert a temporary random number Encrypted ciphertext, A summary of the first communication for the vehicle, For vehicles To the first roadside unit Timestamp of sending information; vehicle Through the public channel Send to first roadside unit ; First roadside unit receive Post-inspection ; In response to The first roadside unit choose and ,calculate and ,in, is a temporary random number, To convert a temporary random number Encrypted ciphertext, a first communication digest for a first roadside unit, First roadside unit Trusted Institutions Timestamp of when the message was sent, First roadside unit The long ID code, First roadside unit The false identity, First roadside unit Authentication credentials for the first roadside unit Will Send to a trusted institution ; Trusted Institutions receive Post-inspection ; In response to The preset second time threshold is not exceeded, and the trusted institution According to vehicle Pseudo-identity Find the vehicle from storage Temporary status ,calculate , )and , and check ,in The first communication digest of the vehicle calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify vehicle Verification successful; Trusted Institutions According to the first roadside unit Pseudo long ID code Find from storage ,calculate , , and , and check ,in, To place the first roadside unit Long ID code Encrypted ciphertext, The first communication digest of the first roadside unit calculated by the trusted institution; in response to both sides of the equation being equal, the trusted institution Verify first roadside unit Verification successful; Trusted Institutions choose ,calculate , and ,in, Trusted institution To the first roadside unit Timestamp of when the message was sent, For encryption The ciphertext, For encryption The ciphertext, A first communication digest for a trusted authority; a trusted authority Will Send to first roadside unit ; First roadside unit receive Post-inspection ; In response to The preset third time threshold is not exceeded, and the first roadside unit calculate , and check ,in A first communication digest of a trusted institution calculated for a first roadside unit; in response to both sides of the equation being equal, the first roadside unit Verify trusted institutions Verification successful; First roadside unit calculate and ,in, is the first communication key; the first roadside unit choose ,calculate ,in First roadside unit The timestamp of sending the message to vehicle 𝑉𝑖, A second communication digest for a trusted authority; a first roadside unit Will Send to vehicle ; vehicle receive Post-inspection ; In response to The vehicle does not exceed the preset fourth time threshold. calculate , and , and verify ,in A second communication digest of the trusted authority calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify trusted institutions The verification is successful, and the first communication key established by the vehicle and the first roadside unit using a trusted institution for mutual authentication is obtained. .

6. The lightweight cross-domain identity authentication method in a vehicle networking environment according to claim 1 is characterized in that: In response to the vehicle to be cross-domain driving to the domain of the second roadside unit, the vehicle to be cross-domain and the second roadside unit perform mutual authentication based on the authentication parameter to establish a second communication key, including: vehicle choose and ,calculate , ,in The random number generated for this communication, To convert random numbers Encrypted ciphertext, The third communication summary for the vehicle, For vehicles To the second roadside unit Timestamp of sending information; vehicle Will Send to second roadside unit ; Second roadside unit receive After that, check ; In response to The preset ninth time threshold is not exceeded, and the second roadside unit According to the vehicle Pseudo-identity Get vehicle information Encrypted ciphertext ,calculate , and , and check ,in The third information summary of the vehicle calculated for the second roadside unit; in response to both sides of the equation being equal, the second roadside unit Successfully verified the vehicle the legality of Second roadside unit choose and ,calculate , and ,in For Encrypted ciphertext, To generate a session key for the second RSU The random number selected, a second communication digest for a second roadside unit, is the second communication key; the second roadside unit Will Send to vehicle ; vehicle receive Post-inspection ; In response to The vehicle calculate , and , and check ,in A second communication digest of a second roadside unit calculated for the vehicle; in response to both sides of the equation being equal, the vehicle Verify Second Roadside Unit The verification is successful, and the second communication key established by the vehicle and the second roadside unit for mutual authentication based on the authentication parameters is obtained. .

7. A lightweight cross-domain identity authentication system in a vehicle networking environment based on the lightweight cross-domain identity authentication method in a vehicle networking environment according to claim 1, characterized in that: including trusted institutions, multiple vehicles, and multiple roadside units, The trusted institution is in communication connection with a plurality of vehicles and a plurality of roadside units, and is used to provide registration and authentication for the vehicles and the roadside units; The roadside unit is connected to a trusted institution for communication, and is used to collect road condition information and regularly upload the collected road condition information to the trusted institution; the roadside unit is connected to a vehicle for communication, and is used to guide the vehicle to drive safely through data interaction.

8. The lightweight cross-domain identity authentication system in the vehicle networking environment according to claim 7 is characterized in that: The vehicle is equipped with an OBU and SGX1; the OBU is used to store general data; the SGX1 is used to store secret data; the roadside unit is equipped with a TPD and SGX2; the TPD is used to store general data; the SGX2 is used to store secret data; the trusted institution is equipped with a database for storing data.

Citation Information

Patent Citations

  • Lightweight anonymous cross-domain batch authentication method for Internet of Vehicles

    CN118474698A