Privacy protection method for VANET against collusion attacks based on certificateless aggregate signature
By adopting certificateless elliptic curve encryption method and binary search algorithm in VANET, the problems of collusion attack and low efficiency of invalid signature recognition are solved, efficient signature verification and security enhancement are achieved, and the security and privacy protection of VANET are improved.
Patent Information
- Application Number
- CN202411758101.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-12-03
AI Technical Summary
Existing certificateless aggregate signature schemes fail to effectively defend against collusion attacks in VANETs, and the invalid signature recognition algorithm is inefficient and cannot accurately identify invalid signatures, resulting in insufficient VANET security and privacy protection.
A certificateless elliptic curve encryption method is adopted to identify collusion attacks through the collaboration of RSU and AS, and a binary search algorithm is used to improve the efficiency of invalid signature recognition. The vehicle's pseudonym and public-private key pair are generated to reduce computing and communication overhead and avoid certificate management and key escrow issues.
It improves the security and signature verification efficiency of VANET, can effectively detect collusion attacks, reduces computing and communication overhead, improves the accuracy and efficiency of signature recognition, and enhances network security and privacy protection.
Smart Images

Figure CN119562249B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle-mounted network security, and in particular to a VANET privacy protection method against collusion attacks based on certificateless aggregate signatures. Background Art
[0002] With advances in communication technology, vehicular ad hoc networks (VANETs) have evolved into practical service platforms for vehicles to communicate with one another, with roads, and with pedestrians. However, as VANETs become more intelligent and networked, security issues are becoming increasingly prominent, often leading to extremely serious consequences. For example, when vehicles are attacked remotely and maliciously controlled, user privacy can be compromised. Attackers can also manipulate vehicle movement through attacks, potentially leading to the mass control of large numbers of connected vehicles, ultimately triggering major social security incidents. In VANETs, authentication technology is one of the key solutions to address vehicle security issues. Given the growing demand for intelligent transportation systems (ITS), VANETs are considered a suitable solution for implementing ITS. Traditional VANET systems consist of a trusted authority (TA), a key generation center (KGC), a roadside unit (RSU), an onboard unit (OBU) embedded in the vehicle, and an application server (AS). There are two representative types of communication in VANETs: vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I). However, both V2V and V2I transmit information, including vehicle location, speed, and surrounding traffic conditions, over open channels. Therefore, attackers can easily access and tamper with this information for malicious purposes, such as stealing user privacy and disrupting traffic by falsifying traffic information. Therefore, before the widespread deployment of VANETs, it is necessary to explore their required security properties, particularly authentication and message integrity. Message signing can effectively meet these requirements.
[0003] To address security attributes such as authentication and privacy protection in VANETs, researchers have proposed numerous signature authentication schemes, including those based on Public Key Infrastructure (PKI), identity-based (ID) encryption, and certificateless public key cryptography (CL-PKC). Furthermore, based on the existing Dedicated Short Range Communications (DSRC) protocol, vehicles must send messages periodically (300ms), requiring VANETs to transmit and verify a large number of messages within a given timeframe. Given the limited network bandwidth and vehicle computing power of VANETs, aggregate signatures are an effective technique for meeting these performance requirements. By aggregating n signatures from different vehicles into a single short signature, computational and communication overhead can be significantly reduced, making them particularly suitable for bandwidth-constrained VANET environments.
[0004] Although many privacy-preserving certificateless aggregate signature schemes have been constructed in VANET applications, most of them are based on bilinear pairing, which significantly increases computational and communication overhead. Among the existing certificateless aggregate signature schemes, most only consider two types of adversary attacks, including malicious KGC attacks and public key substitution attacks, while collusion attacks are usually ignored. In a collusion attack, two malicious vehicles can pass the aggregate signature authentication by forging signatures, even if the aggregated individual signatures are invalid, which will pose a major threat to VANET security. In addition, most of the existing invalid signature recognition algorithms are inefficient and cannot accurately identify invalid signatures because they ignore collusion attacks. Summary of the Invention
[0005] In response to the above-mentioned deficiencies in the existing technology, the present invention proposes a VANET privacy protection method against collusion attacks based on certificateless aggregate signatures based on certificateless methods and aggregate signature technology, aiming to avoid the certificate management overhead and key escrow problems in traditional authentication methods, and provides a new certificateless aggregate signature method.
[0006] The present invention proposes a VANET privacy protection method against collusion attacks based on certificateless aggregate signatures, comprising:
[0007] Step 1: Build a VANET privacy protection model based on certificateless aggregate signatures to resist collusion attacks, including vehicles equipped with on-board units (OBUs), roadside units (RSUs), application servers (ASs), key generation centers (KGCs), and trusted authorities (TAs).
[0008] Step 2: Use elliptic curve cryptography to generate model parameters of the VANET privacy protection model based on certificateless aggregate signature and anti-collusion attack;
[0009] Step 3: The RSU in the VANET privacy protection model against collusion attacks based on certificateless aggregate signature submits a registration application to the TA. After registration is completed, the TA sends the model parameters to the RSU.
[0010] Step 4: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA sends the model parameters to the vehicle v i And save to OBU, TA generates vehicle v i Pseudonymous PID i And send them to vehicle v respectively i and KGC;
[0011] Step 5: When KGC receives the pseudonym PID transmitted by TA i When KGC checks PID i Is it within the valid time period? If not, KGC discards the pseudonym. If so, it generates a vehicle v i The public and private key pair;
[0012] Step 6: When the vehicle v i Generates message m when an event is detected i , using pseudonymous PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m i The signed message package is sent to RSU;
[0013] Step 7: RSU receives vehicle v i Check the timestamp and pseudonym PID of the signed message packet i The valid time period of the signature message packet is verified. If the verification fails, the RSU discards the signature message packet; if the verification passes, the RSU accepts the signature message packet; where PK i For vehicle v i 's public key;
[0014] Step 8: After the RSU receives the signature message packets of n vehicles, it aggregates the signature message packets of n vehicles and sends the signature message packets of n vehicles and the generated aggregate signature σ to the AS;
[0015] Step 9: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet i The AS receives the aggregate signature σ if the verification passes. If the verification fails, the AS sends the aggregate signature σ as an invalid aggregate signature to the RSU.
[0016] Step 10: The AS and RSU use the dichotomy method to collaboratively identify the invalid aggregate signature and obtain all invalid signatures in the invalid aggregate signature. The AS sends the pseudonym of the vehicle corresponding to each invalid signature to the TA and obtains the real identity of the vehicle corresponding to each invalid signature.
[0017] The vehicle equipped with the OBU in step 1 is used to communicate with vehicles equipped with the OBU, roadside units (RSUs) and pedestrians within the coverage area of the dedicated short-range communication (DSRC) technology.
[0018] The roadside unit (RSU) is configured to receive traffic information from all vehicles within the communication range of the RSU, verify the integrity and validity of the traffic information of any vehicle within the communication range of the RSU, and then send the verified traffic information to the trusted authority (TA); aggregate the signatures of all vehicles within the communication range of the RSU and transmit the obtained aggregated signature to the application server (AS);
[0019] The application server AS is used to obtain the vehicle's aggregate signature from the roadside unit RSU through a wired connection and verify the validity of the aggregate signature. For the aggregate signature that passes the verification, the AS uses the aggregate signature and the public and private keys of the AS to detect whether the VANET is subject to a conspiracy attack; for the invalid aggregate signature that fails the verification, the AS sends the invalid aggregate signature as an illegal signature to the trusted authority TA;
[0020] The key generation center KGC is used to generate a partial private key for each vehicle equipped with an OBU;
[0021] The trusted authority TA is used to initialize a VANET privacy protection model based on certificateless aggregate signatures to resist collusion attacks; to provide registration services for roadside units (RSUs) and vehicles equipped with OBUs; to communicate with roadside units (RSUs) via a secure transmission protocol; and to generate a pseudonym for the vehicle and use the pseudonym to reveal the true identity of an illegal signature from an application server (AS).
[0022] The step 2 further comprises:
[0023] Step 2.1: Based on the selected security parameter λ, the key generation center KGC and the trusted authority TA select an elliptic curve E, determine a cyclic group G of order q on the elliptic curve E, and determine the generator P; where q is a large prime number;
[0024] The elliptic curve E is expressed as:
[0025] E:y 2 =x 3 +ax+b(modp)
[0026] Where y and x are unknowns in the elliptic curve equation; a and b are constants defining the elliptic curve, and a,b∈F p , 4a 3 +27b 2 (modp)≠0; F p is a finite field; mod represents the modulo operation; p is a large prime number;
[0027] Step 2.2: KGC selects a random number k as its private key and calculates its public key; TA selects a random number t as its private key and calculates its public key; AS selects a random number s as its private key and calculates its public key; where represents the multiplicative group modulo p;
[0028] Step 2.3: Generate model parameters {G,q,T pub ,K pub ,A pub ,H0,H1,H2,H3,H4,P,G,E}; where T pub is the public key of TA; K pub is the public key of KGC; A pub is the public key of AS; H0, H1, H2, H3 and H4 are all hash functions;
[0029] The step 4 further comprises:
[0030] Step 4.1: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA will send the model parameters to the vehicle v after receiving the registration application i ;
[0031] Step 4.2: Using TA’s public key and vehicle v i Real identity RID i Calculate the pseudonymous first identifier PID i,1 , thereby generating the vehicle authentication message {N i ,PID i,1}, and by vehicle v i Send to TA; n i For vehicle v i A random number is chosen, and Represents the exclusive OR operation;
[0032] The pseudonymous first identifier PID i,1 for:
[0033] PID i,1 =n i P
[0034] Step 4.3: TA saves the received vehicle authentication message {N i ,PID i,1}, use TA's private key t to calculate vehicle v i Real identity RID i , and the calculated real identity RID i Match the real identities of all vehicles stored in TA. If the match fails, it means that RID i Invalid and discarded; if the match is successful, calculate the pseudonym second identifier PID i,2 ;
[0035] The pseudonymous second identifier PID i,2 Expressed as:
[0036]
[0037] Where T i Indicates PID i The effective time period;
[0038] Step 4.4: First identifier PID according to pseudonym i,1 and pseudonymous second identifier PID i,2 Generate vehicle v i Pseudonymous PID i , and the pseudonym PID i Sent to KGC and vehicle v i ;
[0039] The vehicle v i Pseudonymous PID i Expressed as:
[0040] PID i ={PID i,1 ,PID i,2 ,T i};
[0041] The step 5 further comprises:
[0042] Step 5.1: Vehicle v i Pick a random number x i as a secret value, and Calculate vehicle v i Part of the public key X i ;
[0043] Step 5.2: KGC selects a random number r i ,and And based on the random number r i And hash function H1 calculates hash value h 1i ;
[0044] Step 5.3: KGC calculates the hash value h 1i Calculate vehicle v i Part of the private key d i , and generate a partial secret key PPK i Send to vehicle v i ;
[0045] The partial secret key PPK i Expressed as:
[0046] PPK i =(d i ,R i )
[0047] where R i =r i P, r i is a random number selected by KGC, and
[0048] Step 5.4: Vehicle v i Receive PPK i Post-verification partial secret key PPK i Is it legal? If the expression for verifying legality is established, it means that the partial secret key PPK i Legal, vehicle v i Accept partial secret key PPK i ; If the expression for verifying legitimacy does not hold, it means that the partial secret key PPK i Illegal, vehicle v i Discard some PPK keys i ;
[0049] The expression for verifying the legitimacy is:
[0050] d i P=R i +h 1i K pub
[0051] Step 5.5: Vehicle v iAccording to the partial secret key PPK i Generate vehicle v i Public key PK i and private key SK i , and form vehicle v i The public and private key pair;
[0052] The vehicle v i Public key PK i Expressed as:
[0053] PK i =(X i ,R i )
[0054] The vehicle v i The private key SK i Expressed as:
[0055] SK i =(x i ,d i );
[0056] The step 6 further comprises:
[0057] Step 6.1: When the vehicle v i Generates message m when an event is detected i , and get the current timestamp t i ; where m i ∈{0,1} * ;
[0058] Step 6.2: Vehicle v i Pick a random number z i ,and And use the pseudonym PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m i The certificateless signature σ i ;
[0059] The message m i The certificateless signature σ i Expressed as:
[0060] σ i =(Z i ,V i )
[0061] where Z i and V i All are signed without certificate σ i The signature result in , and there are:
[0062] Z i =z i P
[0063] V i =z i +h 2i x i +h 3i d i
[0064] where h 2i and h 3i are the hash values calculated by hash functions H2 and H3 respectively, and there are:
[0065] h 2i =H2(PID i ,X i ,K pub ,R i ,t i )
[0066] h 3i =H3(PID i ,m i ,PK i ,Z i ,t i )
[0067] Step 6.3: Vehicle v i Using vehicle v i Public key, current timestamp t i , message m i The certificateless signature σ i , message m i and vehicle v i Pseudonymous PID i Generate vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i};
[0068] The step 7 further comprises:
[0069] Step 7.1: RSU receives vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i}, verify t i Is it correct? If not, discard the signed message packet. If correct, go to step 7.2.
[0070] Step 7.2: RSU receives the vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i} Calculate the hash values h of hash functions H1, H2 and H3 respectively 1i 、h 2i and h 3i ;
[0071] Step 7.3: RSU uses the hash value h 1i 、h 2i and h 3i Calculate the verification information α of the signature message packet i , if α i ≠0, then RSU discards the signed message packet. If α i =0, then accept the signed message packet;
[0072] Verification information α of the signature message packet i Expressed as:
[0073] α i =V i PZ i -h 2i X i -h 3i (R i +h 1i K pub );
[0074] The aggregate signature σ in step 8 is expressed as:
[0075]
[0076] where Z1, Z2, ..., Z n They represent the signature results of the certificateless signatures of the first, second, and nth vehicles respectively; V represents the aggregated signature value, and there are:
[0077]
[0078] The basis for detecting whether VANET is under collusion attack is:
[0079]
[0080] Among them, V1, V2 and V n Represent the signature results of the certificateless signature of the 1st, 2nd and nth vehicles respectively;
[0081] The step 9 further comprises:
[0082] Step 9.1: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet separately. i Check whether the valid time period is correct. If so, proceed to step 9.2. If not, discard the aggregate signature.
[0083] Step 9.2: AS uses the received aggregate signature σ and the signature message packets of n vehicles to calculate the hash values h of the hash functions H1, H2 and H3 1i 、h 2i and h 3i ;
[0084] Step 9.3: AS calculates the verification information α of the aggregate signature validity based on the aggregate signature σ and the signature message packets of n vehicles. If α = 0, it means that the aggregate signature σ is valid, and step 9.4 is executed; if α ≠ 0, it means that the aggregate signature σ is invalid, and AS sends the aggregate signature as an invalid aggregate signature to the RSU;
[0085] The verification information α of the validity of the aggregate signature is expressed as:
[0086]
[0087] in
[0088] Step 9.4: Set the verification equation of a single vehicle signature and calculate the verification information β of the VANET under collusion attack based on the verification equation of n vehicle signatures and the aggregate signature σ. If β=0, the AS receives the aggregate signature σ and the signature message packet {PK i t i ,σ i ,m i ,PID i}, where i = 1, 2, ..., n; if β ≠ 0, it means that the VANET has been attacked by a conspiracy, and the AS sends the aggregate signature as an invalid aggregate signature to the RSU;
[0089] The verification equation of the single vehicle signature is expressed as:
[0090] M i =V i P=Z i +h 2i X i +h 3i (R i +h 1i K pub )
[0091] The verification information β of the VANET subjected to the conspiracy attack is expressed as:
[0092]
[0093] Among them, M1, M2, M3 and M n The verification equations for the vehicle signatures of the 1st, 2nd, 3rd and nth vehicles respectively;
[0094] The step 10 further comprises:
[0095] Step 10.1: When RSU receives invalid aggregate signature σ from AS * When , the aggregate signature σ will be invalid * The signature message packets of all n vehicles participating in the aggregation are randomly sorted, the middle position of the sorting result is found, and the sorting result is divided into two parts of signatures starting from the middle position. The two parts of signatures are aggregated separately to obtain the re-aggregated signature and And send it to AS;
[0096] Step 10.2: AS receives from RSU and Afterwards, respectively and Verify. If the verification passes, the AS accepts the aggregate signature. If the verification fails, the AS sends the aggregate signature as a new invalid aggregate signature to the RSU and returns to step 10.1.
[0097] The respective and The verification process is as follows: for the reaggregated signature AS check separately Timestamp and pseudonymous PID of each signed message packet i Is the valid time period correct? If not, discard it. If correct, calculate Verification information of the validity of the aggregate signature like Then it means Invalid, AS will Send it to RSU as a new invalid aggregate signature and return to step 10.1; if Then it means Effective, calculate the verification information of VANET under conspiracy attack like Then AS receives the aggregate signature And the signature message package corresponding to the aggregate signature; if Then it means If the AS is attacked by a conspiracy, As a new invalid aggregate signature Send to RSU and return to step 10.1; for the re-aggregated signature The verification method is the same as above The verification method is the same;
[0098] Step 10.3: AS and RSU repeat steps 10.1-10.2 multiple times until an invalid aggregate signature σ is found. * All invalid signatures in AS will use the pseudonym PID of the vehicle corresponding to each invalid signature i Send it to TA, TA receives the pseudonym PID i The real identity of the vehicle corresponding to each invalid signature is retrieved from the TA's database; where i = 1, 2, 3, ..., l, and l represents the number of invalid signatures.
[0099] The beneficial effects of adopting the above technical solution are:
[0100] The method uses a certificateless approach, avoiding the certificate management overhead associated with public key infrastructure-based approaches while also addressing the key escrow issue associated with identity-based encryption. It also utilizes aggregate signature technology to aggregate multiple signatures into a single signature, significantly improving signature verification efficiency. The method avoids traditional bilinear pairing-based approaches, reducing computational and communication overhead.
[0101] Aiming at the problem that traditional certificateless aggregate signature schemes cannot resist collusion attacks, compared with existing certificateless aggregate signature methods, the method of the present invention provides a specific method for detecting collusion attacks, that is, the public and private keys of the application server AS are given during initialization. The public and private keys of the AS can effectively detect collusion attacks in the aggregate verification stage. Multiple malicious vehicles cannot pass the aggregate verification by forging a single signature, which greatly enhances the security of VANET.
[0102] To address the low efficiency and inability of existing invalid signature recognition algorithms to accurately identify invalid signatures, the present invention proposes a highly efficient invalid signature recognition algorithm. Compared to traditional algorithms, this method improves invalid signature recognition by using a binary search and avoiding the recursive verification required by traditional algorithms. This method is not only more efficient but also effectively detects malicious vehicles initiating collusion attacks, significantly improving detection accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0103] Figure 1 Flowchart of the VANET privacy protection method against collusion attacks based on certificateless aggregate signature in this embodiment;
[0104] Figure 2 Schematic diagram of the VANET privacy protection model against collusion attacks based on certificateless aggregate signature in this embodiment;
[0105] Figure 3 A flow chart for generating model parameters in this embodiment;
[0106] Figure 4 This is a flowchart of the TA generating a pseudonym for a vehicle in this embodiment;
[0107] Figure 5 A flowchart for generating a vehicle public and private key pair in this embodiment;
[0108] Figure 6 Flowchart for generating certificateless signature for the vehicle in this embodiment;
[0109] Figure 7 Flowchart of single signature verification performed by RSU on a received certificateless signature in this embodiment;
[0110] Figure 8 This is a flow chart of how AS performs aggregate authentication and detects collusion attacks in this implementation. DETAILED DESCRIPTION
[0111] For ease of understanding of the present application, the specific embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings and embodiments. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present application more thoroughly and comprehensively understood.
[0112] This embodiment is a VANET privacy protection method based on certificateless aggregate signature to resist conspiracy attacks, such as Figure 1 As shown, the method includes the following steps:
[0113] Step 1: Construct a VANET privacy protection model against collusion attacks based on certificateless aggregate signature, including: vehicles equipped with on-board units (OBUs), roadside units (RSUs), application servers (ASs), key generation centers (KGCs), and trusted authorities (TAs).
[0114] In this embodiment, if Figure 2 As shown in Figure 1, the VANET privacy protection model includes the following entities: vehicles equipped with OBUs, roadside units (RSUs), application servers (ASs), key generation centers (KGCs), and trusted authorities (TAs).
[0115] The vehicle equipped with the OBU is used to communicate with other vehicles equipped with the OBU, roadside units (RSUs) and pedestrians within the coverage of the dedicated short range communications (DSRC) technology.
[0116] In this implementation, vehicles equipped with OBUs are the core components of the VANET, enabling intelligent interconnection. Dedicated Short Range Communication (DSRC) is a wireless communication technology that allows vehicles to communicate directly with surrounding infrastructure and other vehicles at high speed and security. DSRC technology can communicate with pedestrian devices, such as smartphones or other DSRC-enabled devices, through the RSUs, enabling information exchange between vehicles and pedestrians.
[0117] The roadside unit RSU is used to receive traffic information of all vehicles within the communication range of the RSU, verify the integrity and validity of the traffic information of any vehicle within the communication range of the RSU, and then send the verified traffic information to the trusted agency TA; aggregate the signatures of all vehicles within the communication range of the RSU and transmit the obtained aggregated signature to the application server AS.
[0118] The traffic information includes: vehicle location, vehicle speed, driving direction and traffic events that occur to the vehicle.
[0119] In this embodiment, roadside units (RSUs) are communication devices deployed on the roadside that can receive traffic information from vehicles within their coverage area and verify the integrity and validity of this traffic information. The integrity and validity verification method is selected based on common practical solutions. For example, the RSU uses Aggregate Message Authentication Code (Aggregate MAC) technology to verify the authenticity and integrity of the message. The RSU can also send valid traffic information to the traffic control center, which can formulate reasonable traffic strategies based on the received information to improve traffic efficiency. There is no fixed standard for the coverage range of the RSU. Most RSUs have a coverage range of 100 to 300 meters in common urban environments.
[0120] The application server AS is used to obtain the vehicle's aggregate signature from the roadside unit RSU through a wired connection and verify the validity of the aggregate signature. For the aggregate signature that passes the verification, the aggregate signature and the public and private keys of the AS are used to detect whether the VANET is subject to a conspiracy attack; for the invalid aggregate signature that fails the verification, the invalid aggregate signature is sent to the trusted authority TA as an illegal signature.
[0121] In this embodiment, an application server (AS) collects information from roadside units (ROUs) via secure wired connections, providing services such as navigation, entertainment, information, safety, intelligent traffic control, remote vehicle diagnostics, and traffic rescue. It is also responsible for verifying aggregate signatures from RSUs. In this embodiment, the AS also uses its public and private keys to detect collusion attacks on the VANET. A collusion attack occurs when attackers collude to compromise network security by forging or tampering with information. A valid aggregate signature ensures the source and integrity of the information. The AS uses this information to analyze network communication behavior, identify abnormal patterns or behaviors, and thus detect potential collusion attacks. If a collusion attack is detected, the AS must initiate an emergency response to address the threat, implement defensive countermeasures, and conduct security performance comparisons. If no collusion attack is detected, the VANET can continue normal operations because the network is deemed secure and unaffected by the collusion attack. When the AS detects invalid or illegal signatures, it sends them to a trusted authority (TA). The TA is responsible for further investigation and handling, including tracing the source of the illegal signature and implementing appropriate security measures to address and prevent such attacks.
[0122] The key generation center KGC is used to generate a partial private key for each vehicle equipped with an OBU.
[0123] In this implementation, the KGC provides a portion of the vehicle's private key in the Certificateless Aggregate Signature (CLAS) technology, while the vehicle itself generates the remaining private key. This design eliminates the certificate escrow issue and is more suitable for VANET environments.
[0124] The trusted authority TA is used to initialize a VANET privacy protection model based on certificateless aggregate signatures to resist collusion attacks; to provide registration services for roadside units (RSUs) and vehicles equipped with OBUs; to communicate with roadside units (RSUs) through a secure transmission protocol; and to generate a pseudonym for the vehicle and use the vehicle's pseudonym to reveal the true identity of an illegal signature from an application server (AS).
[0125] In this embodiment, the trusted authority TA is a trusted third-party organization responsible for initializing the VANET. TA is the registration center for RSU and OBU, providing registration services for RSU and OBU, ensuring that each device is verified and authorized before joining the network and will never be compromised. TA and RSU communicate through a secure transmission protocol to ensure the security and integrity of information transmission. TA is also responsible for generating pseudonyms for vehicles to protect the privacy of the vehicles. The main purpose of the pseudonym is to protect the privacy of the vehicle and prevent the vehicle from being tracked and identified. In the communication between vehicles or between vehicles and roadside units RSU, the pseudonym is used to achieve vehicle identity authentication and privacy protection. Once the vehicle has malicious behavior, the AS sends the illegal signature to TA, and TA can reveal the true identity of the vehicle through the pseudonym.
[0126] Step 2: Use elliptic curve cryptography to generate model parameters of the VANET privacy protection model based on certificateless aggregate signature against collusion attacks.
[0127] In this embodiment, if Figure 3 As shown in FIG, KGC, TA and AS complete the generation of model parameters and master keys, that is, public and private keys.
[0128] Step 2.1: Based on the selected security parameter λ, the key generation center KGC and the trusted authority TA select an elliptic curve E, determine a cyclic group G of order q on the elliptic curve E, and determine the generator P; where q is a large prime number.
[0129] The elliptic curve E is expressed as:
[0130] E:y 2 =x 3 +ax+b(modp) (1)
[0131] Where y and x are unknowns in the elliptic curve equation; a and b are constants defining the elliptic curve, and a,b∈F p , 4a 3 +27b 2 (modp)≠0; F p is a finite field; mod represents the modulo operation; p is a large prime number.
[0132] In this embodiment, the security parameters directly affect the selection of the elliptic curve and the order of the cyclic group. Security parameters generally include the required security level, key length, etc. These parameters determine the complexity and anti-attack capability of the elliptic curve. Based on the security parameter λ, TA and KGC select an elliptic curve E:y 2 =x 3+ax+b(modp), determine a cyclic group G of order q on E, where q is a large prime number. After determining the cyclic group of order q, TA and KGC need to find a point P on the elliptic curve that is the generator of the cyclic group. That is, the point q times P is the point at infinity O, which is the identity element of the group. The choice of point P is very critical because it will be used as the basis for subsequent key generation. All operations are performed modulo p, that is, in the finite field F. p In the p The elements in are integers modulo p. In the above process, the security parameter affects the finite field F p The choice of prime number p directly affects the security of the elliptic curve; the security parameter determines the elliptic curve equation E:y 2 =x 3 The choice of parameters a and b in +ax+b(modp) needs to satisfy certain conditions to ensure that the curve is non-singular, that is, 4a 3 +27b 2 (modp)≠0; the security parameter also influences the choice of the order q of the cyclic group. q is a prime factor of the set of points on the elliptic curve. A prime number that matches the security parameter is usually chosen to ensure the security and efficiency of the system.
[0133] Step 2.2: KGC selects a random number k as its private key and calculates its public key; TA selects a random number t as its private key and calculates its public key; AS selects a random number s as its private key and calculates its public key; where represents the multiplicative group modulo p.
[0134] The public key of the KGC is:
[0135] K pub =kP (2)
[0136] where K pub The public key of KGC.
[0137] The TA's public key is:
[0138] T pub =tP (3)
[0139] Where T pub is the public key of TA.
[0140] The public key of the AS is:
[0141] A pub =sP (4)
[0142] Among them A pub The public key of the AS.
[0143] Step 2.3: Generate model parameters {G,q,T pub ,K pub ,A pub ,H0,H1,H2,H3,H4,P,G,E}.
[0144] In this embodiment, TA and KGC select five one-way hash functions from the SHA-256 hash function library, denoted as: H0, H1, H2, H3, H4; publish the system parameters {G, q, T pub ,K pub ,A pub ,H0,H1,H2,H3,H4,P,G,E}.
[0145] Step 3: In the VANET privacy protection model against collusion attacks based on certificateless aggregate signature, the RSU submits a registration application to the TA. After the registration is completed, the TA sends the model parameters to the RSU.
[0146] Step 4: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA sends the model parameters to the vehicle v i And save to OBU, TA generates vehicle v i Pseudonymous PID i And send them to vehicle v respectively i and KGC.
[0147] In this embodiment, if Figure 4 As shown, TA generates a pseudonym PID for the vehicle after submitting the registration application i .
[0148] Step 4.1: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA will send the model parameters to the vehicle v after receiving the registration application i .
[0149] Step 4.2: Using TA’s public key and vehicle v i Real identity RID i Calculate the pseudonymous first identifier PID i,1 , thereby generating the vehicle authentication message {N i ,PID i,1}, and by vehicle v i Send to TA; n i For vehicle v i A random number is chosen, and Represents the exclusive OR operation.
[0150] The pseudonymous first identifier PID i,1 for:
[0151] PID i,1 =n i P (5)
[0152] In this embodiment, the vehicle v i Random selection PID for calculating the pseudonym i,1 .RID i Is the vehicle v i The real identity of the vehicle is stored in its database. In most cases, the vehicle will maintain its own database for storing and managing the vehicle's identity information. i Represents vehicle v i The intermediate calculation result is obtained by converting the random number n i Multiply by TA's public key T pub Generate a value that has nothing to do with the identity, and then compare it with the real identity RID i Perform an XOR operation to protect your true identity from being directly disclosed. XOR is a common binary operator that compares two numbers bit by bit. If the two bits have the same value, the result is 0; if they are different, the result is 1.
[0153] Step 4.3: TA saves the received vehicle authentication message {N i ,PID i,1}, use TA's private key t to calculate vehicle v i Real identity RID i , and the calculated real identity RID i Match the real identities of all vehicles stored in TA. If the match fails, it means that RID i Invalid and discarded; if the match is successful, calculate the pseudonym second identifier PID i,2 .
[0154] The pseudonymous second identifier PID i,2 Expressed as:
[0155]
[0156] Where T i Indicates PID i The effective time period.
[0157] Step 4.4: First identifier PID according to pseudonym i,1 and pseudonymous second identifier PID i,2 Generate vehicle v iPseudonymous PID i , and the pseudonym PID i Sent to KGC and vehicle v i .
[0158] The vehicle v i Pseudonymous PID i Expressed as:
[0159] PID i ={PID i,1 ,PID i,2 ,T i} (7)
[0160] Step 5: When KGC receives the pseudonym PID transmitted by TA i When KGC checks PID i Is it within the valid time period? If not, KGC discards the pseudonym. If so, it generates a vehicle v i The public and private key pair.
[0161] In this embodiment, if Figure 5 As shown, when the vehicle v i Transmit pseudonymous PID to KGC i When KGC first checks the PID i Is it within the valid time period? If not, KGC will discard it. Otherwise, output v i Part of the private key.
[0162] Step 5.1: Vehicle v i Pick a random number x i as a secret value, and Calculate vehicle v i Part of the public key X i .
[0163] The vehicle v i Part of the public key X i for:
[0164] X i =x i P (8)
[0165] Step 5.2: KGC selects a random number r i ,and And based on the random number r i And hash function H1 calculates hash value h 1i .
[0166] The hash value h 1i Expressed as:
[0167] h 1i =H1(PID i,R i ,K pub ,X i ) (9)
[0168] where R i =r i P.
[0169] Step 5.3: KGC calculates the hash value h 1i Calculate vehicle v i Part of the private key d i , and generate a partial secret key PPK i Send to vehicle v i .
[0170] The vehicle v i Part of the private key d i Expressed as:
[0171] d i =r i +kh 1i (10)
[0172] The partial secret key PPK i Expressed as:
[0173] PPK i =(d i ,R i ) (11)
[0174] Step 5.4: Vehicle v i Receive PPK i Post-verification partial secret key PPK i Is it legal? If the expression for verifying legality is established, it means that the partial secret key PPK i Legal, vehicle v i Accept partial secret key PPK i ; If the expression for verifying legitimacy does not hold, it means that the partial secret key PPK i Illegal, vehicle v i Discard some PPK keys i .
[0175] The expression for verifying the legitimacy is:
[0176] d i P=R i +h 1i K pub (12)
[0177] In this embodiment, the formula d is calculated i P=R i +h 1i K pubIs it established to verify PPK i If established, the vehicle accepts PPK i , otherwise discarded.
[0178] Step 5.5: Vehicle v i According to the partial secret key PPK i Generate vehicle v i Public key PK i and private key SK i , and form vehicle v i The public and private key pair.
[0179] The vehicle v i Public key PK i Expressed as:
[0180] PK i =(X i ,R i ) (13)
[0181] The vehicle v i The private key SK i Expressed as:
[0182] SK i =(x i ,d i ) (14)
[0183] Step 6: When the vehicle v i Generates message m when an event is detected i , using pseudonymous PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m i The signed message package is sent to the RSU.
[0184] Step 6.1: When the vehicle v i Generates message m when an event is detected i , and get the current timestamp t i ; where m i ∈{0,1} * .
[0185] Step 6.2: Vehicle v i Pick a random number z i ,and And use the pseudonym PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m iThe certificateless signature σ i .
[0186] The message m i The certificateless signature σ i Expressed as:
[0187] σ i =(Z i ,V i ) (15)
[0188] where Z i and V i All are signed without certificate σ i The signature result in , and there are:
[0189] Z i =z i P (16)
[0190] V i =z i +h 2i x i +h 3i d i (17)
[0191] where h 2i and h 3i are the hash values calculated by hash functions H2 and H3 respectively, and there are:
[0192] h 2i =H2(PID i ,X i ,K pub ,R i ,t i ) (18)
[0193] h 3i =H3(PID i ,m i ,PK i ,Z i ,t i ) (19)
[0194] In this embodiment, if Figure 6 As shown in Figure 1, when a vehicle detects a specific event, such as a traffic accident or road condition, it generates an event message and signs it to report it to surrounding vehicles or roadside units (RSUs). 2i and h 3i Calculated by hash functions H2 and H3 respectively, they are used to protect the integrity of the signature and bind information such as message and timestamp; V i One of the signature results, used for the verification process of signature without certificate.
[0195] Step 6.3: Vehicle v i Using vehicle v i The public key and current timestamp t i , message m i The certificateless signature σ i , message m i and vehicle v i Pseudonymous PID i Generate vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i}.
[0196] In this embodiment, the vehicle v i The generated signature message package {PK i ,t i ,σ i ,m i ,PID i}Sent to nearby RSUs for verification and aggregation.
[0197] Step 7: RSU receives vehicle v i Check the timestamp and pseudonym PID of the signed message packet i The RSU verifies the signature message packet. If the verification fails, the RSU discards the signature message packet. If the verification passes, the RSU accepts the signature message packet.
[0198] In this embodiment, if Figure 7 As shown, RSU receives vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i}, check t i and PID i The effective time period T i Is the time period correct? If not, RSU will discard the signed message packet; if correct, RSU will verify the single signature.
[0199] Step 7.1: RSU receives vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i}, verify t iCheck whether it is correct. If not, discard the signature message packet. If correct, execute step 7.2.
[0200] Step 7.2: RSU receives the vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i} Calculate the hash values h of hash functions H1, H2 and H3 respectively 1i 、h 2i and h 3i .
[0201] h 1i =H1(PID i ,R i ,K pub ,X i ) (20)
[0202] h 2i =H2(PID i ,X i ,K pub ,R i ,t i ) (twenty one)
[0203] h 3i =H3(PID i ,m i ,PK i ,Z i ,t i ) (twenty two)
[0204] In this embodiment, h 1i 、h 2i 、h 3i Represents the calculation results of different hash functions, which are used to ensure the binding and integrity of messages, identities, and signatures.
[0205] Step 7.3: RSU uses the hash value h 1i 、h 2i and h 3i Calculate the verification information α of the signature message packet i , if α i ≠0, then RSU discards the signed message packet. If α i =0, then the signed message packet is accepted.
[0206] Verification information α of the signature message packet i Expressed as:
[0207] α i =V i PZi -h 2i X i -h 3i (R i +h 1i K pub ) (twenty three)
[0208] In this embodiment, RSU calculates the signature verification information α i , if α i =0, the signature verification is successful and the RSU accepts the signed message packet.
[0209] Step 8: After the RSU receives the signature message packets of n vehicles, it aggregates the signature message packets of n vehicles and sends the signature message packets of n vehicles and the generated aggregate signature σ to the AS.
[0210] The aggregate signature σ is expressed as:
[0211]
[0212] where Z1, Z2, ..., Z n They represent the signature results of the certificateless signatures of the first, second, and nth vehicles respectively; V represents the aggregated signature value, which is the sum of the signatures of n vehicles, and has:
[0213]
[0214] The basis for detecting whether VANET is under collusion attack is:
[0215]
[0216] Among them, V1, V2 and V n Represent the signature results of the certificateless signature of the 1st, 2nd and nth vehicles respectively.
[0217] In this embodiment, RSU will pass a large number of signature message packets {PK i ,t i ,σ i ,m i ,PID i}, where i = 1, 2, ..., n is aggregated, and the aggregate signature and the signature message packet corresponding to the individual signatures in the aggregate signature are sent {PK i ,t i ,σ i ,m i ,PID i} to AS for verification.
[0218] Step 9: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet i The AS receives the aggregate signature σ if the verification passes. If the verification fails, the AS sends the aggregate signature σ as an invalid aggregate signature to the RSU.
[0219] In this embodiment, if Figure 8 As shown, when AS receives the aggregate signature and information {PK i ,t i ,σ i ,m i ,PID i}(i=1,2,...,n), verify each message t i Whether it is fresh, and the corresponding pseudonym PID i T i If they are not fresh or correct, AS discards them. Otherwise, AS performs aggregate verification and detects whether it is subject to collusion attacks.
[0220] Step 9.1: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet separately. i The validity period of the aggregate signature is correct. If correct, execute step 9.2; if incorrect, discard the aggregate signature.
[0221] Step 9.2: AS uses the received aggregate signature σ and the signature message packets of n vehicles to calculate the hash values h of the hash functions H1, H2 and H3 1i 、h 2i and h 3i .
[0222] In this embodiment, the hash value h 1i 、h 2i and h 3i The calculation method is the same as formula (20)-(22).
[0223] Step 9.3: AS calculates the verification information α of the validity of the aggregate signature based on the aggregate signature σ and the signature message packets of n vehicles. If α = 0, it means that the aggregate signature σ is valid, and step 9.4 is executed; if α ≠ 0, it means that the aggregate signature σ is invalid, and AS sends the aggregate signature as an invalid aggregate signature to RSU.
[0224] The verification information α of the validity of the aggregate signature is expressed as:
[0225]
[0226] in
[0227] Step 9.4: Set the verification equation of a single vehicle signature and calculate the verification information β of the VANET under collusion attack based on the verification equation of n vehicle signatures and the aggregate signature σ. If β=0, the AS receives the aggregate signature σ and the signature message packet {PK i t i ,σ i ,m i ,PID i}, where i = 1, 2, ..., n; if β ≠ 0, it means that the VANET is attacked by a conspiracy, and the AS sends the aggregate signature to the RSU as an invalid aggregate signature.
[0228] The verification equation of the single vehicle signature is expressed as:
[0229] M i =V i P=Z i +h 2i X i +h 3i (R i +h 1i K pub ) (27)
[0230] The verification information β of the VANET subjected to the conspiracy attack is expressed as:
[0231]
[0232] Among them, M1, M2, M3 and M n Represent the verification equations of the vehicle signatures of the 1st, 2nd, 3rd and nth vehicles respectively.
[0233] In this embodiment, the verification equation M of a single vehicle signature is set i , used to verify whether each signature meets the standards of the aggregate signature; calculate the verification information β of the VANET being attacked by collusion, which is used to detect whether the VANET is attacked by collusion. If β=0, the AS accepts the aggregate signature σ and the {PK i t i ,σ i ,m i ,PID i If it is not 0, it means that the VANET is attacked by a conspiracy, and the AS discards the aggregate signature.
[0234] Step 10: AS and RSU use the dichotomy method to collaboratively identify the invalid aggregate signature and obtain all invalid signatures in the invalid aggregate signature. AS sends the pseudonym of the vehicle corresponding to each invalid signature to TA and obtains the real identity of the vehicle corresponding to each invalid signature.
[0235] In this embodiment, when the AS finds that the aggregate signature verification fails, the AS calculates the verification information α of the aggregate signature validity corresponding to the aggregate signature. * ≠0 or the verification information β of the VANET corresponding to the aggregate signature being attacked by collusion * ≠0, the invalid aggregate signature σ * The AS and RSU collaborate to identify invalid aggregate signatures that cause aggregate verification failures, find individual invalid signatures within the invalid aggregate signatures, and send the pseudonyms that signed these signatures to the TA. The TA will reveal the true identities of these pseudonyms.
[0236] Step 10.1: When RSU receives invalid aggregate signature σ from AS * When , the aggregate signature σ will be invalid * The signature message packets of all n vehicles participating in the aggregation are randomly sorted, the middle position of the sorting result is found, and the sorting result is divided into two parts of signatures starting from the middle position. The two parts of signatures are aggregated separately to obtain the re-aggregated signature and And send it to AS.
[0237] In this embodiment, the invalid aggregate signature σ * Randomly sort all the signatures participating in the aggregation, divide all the signatures into two parts starting from the middle position and re-aggregate them according to the method in step 8, and re-aggregate the signatures and Sent to AS. The middle position is determined as follows:
[0238]
[0239] Step 10.2: AS receives from RSU and Afterwards, respectively and Verification is performed. If the verification passes, the AS accepts the aggregate signature. If the verification fails, the AS sends the aggregate signature as a new invalid aggregate signature to the RSU and returns to step 10.1.
[0240] The respective and The verification process is as follows: for the reaggregated signature AS check separately Timestamp and pseudonymous PID of each signed message packet i Is the valid time period correct? If not, discard it. If correct, calculate Verification information of the validity of the aggregate signature like Then it means Invalid, AS will Send it to RSU as a new invalid aggregate signature and return to step 10.1; if Then it means Effective, calculate the verification information of VANET under conspiracy attack like Then AS receives the aggregate signature And the signature message package corresponding to the aggregate signature; if Then it means If the AS is attacked by a conspiracy, As a new invalid aggregate signature Send to RSU and return to step 10.1; for the re-aggregated signature The verification method is the same as above The verification method is similar.
[0241] In this embodiment, the aggregation verification method in step 9 is used to respectively and Verify the reaggregated signature AS check separately Timestamp and pseudonymous PID of each signed message packet i Is the valid time period correct? If not, discard it. If correct, calculate Verification information of the validity of the aggregate signature like Then it means Invalid, AS will Send it to RSU as a new invalid aggregate signature and return to step 10.1; if Then it means Effective, calculate the verification information of VANET under conspiracy attack like Then AS receives the aggregate signature And the signature message package corresponding to the aggregate signature σ; if Then it means If the AS is attacked by a conspiracy, As a new invalid aggregate signature Send to RSU and return to step 10.1. For the re-aggregated signature The verification method is the same as above The verification method is similar to that of AS. Timestamp and pseudonymous PID of each signed message packet i Is the valid time period correct? If not, discard it. If correct, calculate Verification information of the validity of the aggregate signature like Then it means Invalid, AS will Send it to RSU as a new invalid aggregate signature and return to step 10.1; if Then it means Effective, calculate the verification information of VANET under conspiracy attack like Then AS receives the aggregate signature And the signature message package corresponding to the aggregate signature; if Then it means If the AS is attacked by a conspiracy, Send it to RSU as a new invalid aggregate signature and return to step 10.1.
[0242] Step 10.3: AS and RSU repeat steps 10.1-10.2 multiple times until an invalid aggregate signature σ is found. * All invalid signatures in AS will use the pseudonym PID of the vehicle corresponding to each invalid signature i Send it to TA, TA receives the pseudonym PID i The real identity of the vehicle corresponding to each invalid signature is retrieved from the TA's database; where i = 1, 2, 3, ..., l, and l represents the number of invalid signatures.
[0243] In this embodiment, the AS and RSU repeat steps 10.1 and 10.2 until all invalid signatures are found. l is the number of invalid signatures, and AS sends the corresponding illegal pseudonym Give it to TA, and TA will reveal the true identity of the illegal pseudonym.
[0244] In this embodiment, the TA uses a binary search algorithm for invalid signatures to reveal the true identity of the invalid pseudonym. The specific steps are shown in Table 1 below.
[0245] Table 1 Binary search algorithm for invalid signatures
[0246]
[0247]
[0248] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope defined by the claims of the present invention.
Claims
1. A VANET privacy protection method against collusion attacks based on certificateless aggregate signatures, characterized in that: The method comprises the following steps: Step 1: Build a VANET privacy protection model based on certificateless aggregate signatures to resist collusion attacks, including vehicles equipped with on-board units (OBUs), roadside units (RSUs), application servers (ASs), key generation centers (KGCs), and trusted authorities (TAs). Step 2: Use elliptic curve cryptography to generate model parameters of the VANET privacy protection model based on certificateless aggregate signature and anti-collusion attack; Step 3: The RSU in the VANET privacy protection model against collusion attacks based on certificateless aggregate signature submits a registration application to the TA. After registration is completed, the TA sends the model parameters to the RSU. Step 4: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA sends the model parameters to the vehicle v i And save to OBU, TA generates vehicle v i Pseudonymous PID i And send them to vehicle v respectively i and KGC; Step 5: When KGC receives the pseudonym PID transmitted by TA i When KGC checks PID i Is it within the valid time period? If not, KGC discards the pseudonym. If so, it generates a vehicle v i The public and private key pair; Step 6: When the vehicle v i Generates message m when an event is detected i , using pseudonymous PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m i The signed message package is sent to RSU; Step 7: RSU receives vehicle v i Check the timestamp and pseudonym PID of the signed message packet i The valid time period of the signature message packet is verified. If the verification fails, the RSU discards the signature message packet. If the verification is successful, the RSU accepts the signed message packet; Step 8: After the RSU receives the signature message packets of n vehicles, it aggregates the signature message packets of n vehicles and sends the signature message packets of n vehicles and the generated aggregate signature σ to the AS; Step 9: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet i The AS receives the aggregate signature σ if the verification passes. If the verification fails, the AS sends the aggregate signature σ as an invalid aggregate signature to the RSU. Step 10: AS and RSU use the dichotomy method to collaboratively identify the invalid aggregate signature and obtain all invalid signatures in the invalid aggregate signature. AS sends the pseudonym of the vehicle corresponding to each invalid signature to TA and obtains the real identity of the vehicle corresponding to each invalid signature.
2. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 1 is characterized in that: The vehicle equipped with the OBU in step 1 is used to communicate with vehicles equipped with the OBU, roadside units (RSUs) and pedestrians within the coverage area of the dedicated short-range communication (DSRC) technology. The roadside unit (RSU) is configured to receive traffic information from all vehicles within the communication range of the RSU, verify the integrity and validity of the traffic information of any vehicle within the communication range of the RSU, and then send the verified traffic information to the trusted authority (TA); aggregate the signatures of all vehicles within the communication range of the RSU and transmit the obtained aggregated signature to the application server (AS); The application server AS is used to obtain the vehicle's aggregate signature from the roadside unit RSU through a wired connection and verify the validity of the aggregate signature. For the verified aggregate signature, the aggregate signature and the public and private keys of the AS are used to detect whether the VANET is subject to a conspiracy attack; For invalid aggregate signatures that fail verification, the invalid aggregate signature is sent to the trusted authority TA as an illegal signature; The key generation center KGC is used to generate a partial private key for each vehicle equipped with an OBU; The trusted authority TA is used to initialize the VANET privacy protection model against collusion attacks based on certificateless aggregate signature; Used to provide registration services for roadside units (RSUs) and vehicles equipped with OBUs; Used to communicate with the roadside unit RSU through a secure transmission protocol; It is used to generate a pseudonym for the vehicle and use the pseudonym of the vehicle to reveal the true identity of the illegal signature from the application server AS.
3. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 2 is characterized in that: The step 2 further comprises: Step 2.1: Based on the selected security parameter λ, the key generation center KGC and the trusted authority TA select an elliptic curve E, determine a cyclic group G of order q on the elliptic curve E, and determine the generator P; where q is a large prime number; The elliptic curve E is expressed as: E:y 2 =x 3 +ax+b(modp) Where y and x are unknowns in the elliptic curve equation; a and b are constants defining the elliptic curve, and a,b∈F p , 4a 3 +27b 2 (modp)≠0; F p is a finite field; mod represents the modulo operation; p is a large prime number; Step 2.2: KGC selects a random number k as its private key and calculates its public key; TA selects a random number t as its private key and calculates its public key; AS selects a random number s as its private key and calculates its public key; where represents the multiplicative group modulo p; Step 2.3: Generate model parameters {q,T pub ,K pub ,A pub ,H0,H1,H2,H3,H4,P,G,E}; where T pub is the public key of TA; K pub is the public key of KGC; A pub is the public key of AS; H0, H1, H2, H3 and H4 are all hash functions.
4. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 3 is characterized in that: The step 4 further comprises: Step 4.1: For the i-th vehicle v in the VANET privacy protection model based on certificateless aggregate signature against collusion attack i , vehicle v i Submit a registration application to TA, and TA will send the model parameters to the vehicle v after receiving the registration application i ; Step 4.2: Using TA’s public key and vehicle v i Real identity RID i Calculate the pseudonymous first identifier PID i,1 , thereby generating the vehicle authentication message {N i ,PID i,1 }, and by vehicle v i Send to TA; n i For vehicle v i A random number is chosen, and Represents the exclusive OR operation; The pseudonymous first identifier PID i,1 for: PID i,1 =n i P Step 4.3: TA saves the received vehicle authentication message {N i ,PID i,1 }, use TA's private key t to calculate vehicle v i Real identity RID i , and the calculated real identity RID i Match the real identities of all vehicles stored in TA. If the match fails, it means that RID i Invalid and discarded; if the match is successful, calculate the pseudonym second identifier PID i,2 ; The pseudonymous second identifier PID i,2 Expressed as: Where T i Indicates PID i The effective time period; Step 4.4: First identifier PID according to pseudonym i,1 and pseudonymous second identifier PID i,2 Generate vehicle v i Pseudonymous PID i , and the pseudonym PID i Sent to KGC and vehicle v i ; The vehicle v i Pseudonymous PID i Expressed as: PID i ={PID i,1 ,PID i,2 ,T i }。 5. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 4 is characterized in that: The step 5 further comprises: Step 5.1: Vehicle v i Pick a random number x i as a secret value, and Calculate vehicle v i Part of the public key X i ; Step 5.2: KGC selects a random number r i ,and And based on the random number r i And hash function H1 calculates hash value h 1i ; Step 5.3: KGC calculates the hash value h 1i Calculate vehicle v i Part of the private key d i , and generate a partial secret key PPK i Send to vehicle v i ; The partial secret key PPK i Expressed as: PPK i =(d i ,R i ) where R i =r i P, r i is a random number selected by KGC, and Step 5.4: Vehicle v i Receive PPK i Post-verification partial secret key PPK i Is it legal? If the expression for verifying legality is established, it means that the partial secret key PPK i Legal, vehicle v i Accept partial secret key PPK i ; If the expression for verifying legitimacy does not hold, it means that the partial secret key PPK i Illegal, vehicle v i Discard some PPK keys i ; The expression for verifying the legitimacy is: d i P=R i +h 1i K pub Step 5.5: Vehicle v i According to the partial secret key PPK i Generate vehicle v i Public key PK i and private key SK i , and form vehicle v i The public and private key pair; The vehicle v i Public key PK i Expressed as: PK i =(X i ,R i ) The vehicle v i The private key SK i Expressed as: SK i =(x i ,d i )。 6. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 5 is characterized in that: The step 6 further comprises: Step 6.1: When the vehicle v i Generates message m when an event is detected i , and get the current timestamp t i ; where m i ∈{0,1} * ; Step 6.2: Vehicle v i Pick a random number z i ,and And use the pseudonym PID i 、Vehicle i The public and private key pair and the current timestamp t i For message m i Sign and generate message m i The certificateless signature σ i ; The message m i The certificateless signature σ i Expressed as: σ i =(Z i ,V i ) where Z i and V i All are signed without certificate σ i The signature result in , and there are: WITH i =z i P V i =z i +h 2i x i +h 3i d i where h 2i and h 3i are the hash values calculated by hash functions H2 and H3 respectively, and there are: h 2i =H2(PID i ,X i ,K pub ,R i ,t i ) h 3i =H3(PID i ,m i ,PK i ,Z i ,t i ) Step 6.3: Vehicle v i Using vehicle v i The public key and current timestamp t i , message m i The certificateless signature σ i , message m i and vehicle v i Pseudonymous PID i Generate vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i }.
7. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 6 is characterized in that: The step 7 further comprises: Step 7.1: RSU receives vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i }, verify t i Is it correct? If not, discard the signed message packet. If correct, go to step 7.
2. Step 7.2: RSU receives the vehicle v i The signature message package {PK i ,t i ,σ i ,m i ,PID i } Calculate the hash values h of hash functions H1, H2 and H3 respectively 1i 、h 2i and h 3i ; Step 7.3: RSU uses the hash value h 1i 、h 2i and h 3i Calculate the verification information α of the signature message packet i , if α i ≠0, then RSU discards the signed message packet. If α i =0, then accept the signed message packet; Verification information α of the signature message packet i Expressed as: α i =V i P-Z i -h 2i X i -h 3i (R i +h 1i K pub )。 8. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 7 is characterized in that: The aggregate signature σ in step 8 is expressed as: where Z1, Z2, ..., Z n They represent the signature results of the certificateless signatures of the first, second, and nth vehicles respectively; V represents the aggregated signature value, and there are: The basis for detecting whether VANET is under collusion attack is: Among them, V1, V2 and V n Represent the signature results of the certificateless signature of the 1st, 2nd and nth vehicles respectively.
9. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 8 is characterized in that: The step 9 further comprises: Step 9.1: After receiving the aggregate signature σ and the signature message packets of n vehicles, AS checks the timestamp and pseudonym PID of each signature message packet separately. i Check whether the valid time period is correct. If so, proceed to step 9.
2. If not, discard the aggregate signature. Step 9.2: AS uses the received aggregate signature σ and the signature message packets of n vehicles to calculate the hash values h of the hash functions H1, H2 and H3 1i 、h 2i and h 3i ; Step 9.3: AS calculates the verification information α of the aggregate signature validity based on the aggregate signature σ and the signature message packets of n vehicles. If α = 0, it means that the aggregate signature σ is valid, and step 9.4 is executed; if α ≠ 0, it means that the aggregate signature σ is invalid, and AS sends the aggregate signature as an invalid aggregate signature to the RSU; The verification information α of the validity of the aggregate signature is expressed as: in Step 9.4: Set the verification equation of a single vehicle signature and calculate the verification information β of the VANET under collusion attack based on the verification equation of n vehicle signatures and the aggregate signature σ. If β=0, the AS receives the aggregate signature σ and the signature message packet {PK i t i ,σ i ,m i ,PID i }, where i = 1, 2, ..., n; if β ≠ 0, it means that the VANET has been attacked by a conspiracy, and the AS sends the aggregate signature as an invalid aggregate signature to the RSU; The verification equation of the single vehicle signature is expressed as: M i =V i P=Z i +h 2i X i +h 3i (R i +h 1i K pub ) The verification information β of the VANET subjected to the conspiracy attack is expressed as: Among them, M1, M2, M3 and M n Represent the verification equations of the vehicle signatures of the 1st, 2nd, 3rd and nth vehicles respectively.
10. The VANET privacy protection method against collusion attacks based on certificateless aggregate signature according to claim 9 is characterized in that: The step 10 further comprises: Step 10.1: When RSU receives invalid aggregate signature σ from AS * When , the aggregate signature σ will be invalid * The signature message packets of all n vehicles participating in the aggregation are randomly sorted, the middle position of the sorting result is found, and the sorting result is divided into two parts of signatures starting from the middle position. The two parts of signatures are aggregated separately to obtain the re-aggregated signature and And send it to AS; Step 10.2: AS receives from RSU and Afterwards, respectively and Verify. If the verification passes, the AS accepts the aggregate signature. If the verification fails, the AS sends the aggregate signature as a new invalid aggregate signature to the RSU and returns to step 10.
1. The respective and The verification process is as follows: for the reaggregated signature AS check separately Timestamp and pseudonymous PID of each signed message packet i Is the valid time period correct? If not, discard it. If correct, calculate Verification information of the validity of the aggregate signature like Then it means Invalid, AS will Send it to RSU as a new invalid aggregate signature and return to step 10.1; if Then it means Effective, calculate the verification information of VANET under conspiracy attack like Then AS receives the aggregate signature And the signature message package corresponding to the aggregate signature; if Then it means If the AS is attacked by a conspiracy, As a new invalid aggregate signature Send to RSU and return to step 10.1; for the re-aggregated signature The verification method is the same as above The verification method is the same; Step 10.3: AS and RSU repeat steps 10.1-10.2 multiple times until an invalid aggregate signature σ is found. * All invalid signatures in AS will use the pseudonym PID of the vehicle corresponding to each invalid signature i Send it to TA, TA receives the pseudonym PID i The real identity of the vehicle corresponding to each invalid signature is retrieved from the TA's database; where i = 1, 2, 3, ..., l, and l represents the number of invalid signatures.
Citation Information
Patent Citations
Method suitable for safety communication and conditional privacy protection authentication of vehicle-mounted ad hoc network
CN115379418A
Message recoverable aggregation signature method capable of resisting collusion attack
CN117134984A