A blockchain-based cross-domain authentication system for vehicle networking identities
By adopting a blockchain-based identity cross-domain authentication system in the Internet of Vehicles system, combining digital signatures and biometric verification, real-time monitoring and dynamic adjustment, the problem of low security in the face of attacks is solved, and higher security and stability are achieved.
Patent Information
- Application Number
- CN202510314743.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The existing Internet of Vehicle authentication system is difficult to effectively defend against dictionary attacks and brute-force cracking attacks, resulting in low system security.
The blockchain-based cross-domain authentication system for the identity of the Internet of Vehicles is adopted. Through the identity management module, the blockchain network module, the authentication service module and the data sharing module, combined with digital signature verification and biometric verification, the signature request frequency and random number generation mode are monitored in real time, and the blockchain node deployment is dynamically adjusted.
Effectively resist collision attacks, ensure system security and data integrity, improve system security and stability, support interoperability and data sharing between different trust domains, and simplify the authentication process.
Smart Images

Figure CN119854027B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Vehicles, and in particular to an Internet of Vehicles identity cross-domain authentication system based on blockchain. Background Art
[0002] The Internet of Vehicles is a network that takes moving vehicles as the perception objects. Different regions are divided according to geographical locations, and each region is independent. Different regions are managed by their respective trusted institutions. By means of communication technology, network connections between vehicles and cloud platforms, vehicles and vehicles, vehicles and roads, and vehicles and people are realized, so as to improve the traffic operation efficiency; blockchain is a chain data structure generated and combined in chronological order of blocks, with the characteristics of being tamper-proof, transaction retrievable, high security, and strong privacy; with the continuous development of blockchain technology, the application of blockchain technology in the field of authentication is increasing.
[0003] With the rapid increase in the number and popularity of Internet of Vehicles application services and the continuous increase in the number of users, the security of the Internet of Vehicles environment is an issue that needs attention; for the Internet of Vehicles system, there is a risk that vehicle information may be stolen and tampered with, which further affects the healthy operation of the Internet of Vehicles system; intelligent vehicles have the ability to communicate with other entities in the network and can share vehicle status, road conditions, and traffic events and other information with other vehicles, which enables drivers to obtain real-time traffic information, thereby planning the best driving route, improving the driving experience and safety, and effectively avoiding traffic congestion and accidents. However, while the Internet of Vehicles brings convenience to people's lives, it also brings new hidden dangers. The openness of its communication makes the network vulnerable to malicious attacks by adversaries, which poses a huge threat to the secure operation of the network and the privacy of users. Anonymous authentication schemes allow vehicles to authenticate their identities without revealing their privacy, which has a positive significance for the development and application of the Internet of Vehicles.
[0004] The Chinese patent document with the publication number CN119364359A discloses a lightweight cross - domain identity authentication method and system in a vehicle - to - everything (V2X) environment. The method includes: vehicles and each roadside unit register with a trusted authority; the vehicle and the first roadside unit authenticate each other to establish a first communication key; the vehicle to cross the domain uses the first communication key to send a cross - domain notice to the first roadside unit, and the first roadside unit sends the cross - domain notice to the second roadside unit; the second roadside unit determines whether it is the first communication with the vehicle to cross the domain based on the cross - domain notice; if so, the second roadside unit obtains the authentication parameters of the vehicle to cross the domain; if not, the second roadside unit reads the authentication parameters of the vehicle to cross the domain; when the vehicle to cross the domain travels into the domain of the second roadside unit, the vehicle to cross the domain and the second roadside unit authenticate each other based on the authentication parameters to establish a second communication key. It can be seen that existing authentication schemes, such as the public - key infrastructure - based scheme and the identity - based scheme, respectively have difficulties in maintaining the certificate revocation list and problems of key and pseudonym escrow. In addition, the privacy problems of centralized management and cross - domain authentication also greatly limit the development of the vehicle - to - everything network. Moreover, in the signature verification process of existing cross - domain authentication systems, the lack of combination with the monitoring results of the signature process makes it difficult to detect the existence of anti - dictionary - attack and anti - brute - force - attack in a timely manner, resulting in low authentication security. Summary of the Invention
[0005] To this end, the present invention provides a blockchain - based vehicle - to - everything identity cross - domain authentication system to overcome the problem in the prior art that the lack of combination with the digital signature process verification makes it difficult to effectively prevent dictionary attacks and brute - force attacks, resulting in low system security.
[0006] To achieve the above object, the present invention provides a blockchain - based vehicle - to - everything identity cross - domain authentication system,
[0007] An identity management module, which is used to store and manage the identity information of vehicles and users;
[0008] A blockchain network module, which is used to store the identity identifiers of each vehicle and user in the form of blockchain certificates, and store the access records on the blockchain;
[0009] An authentication service module, which is used to receive cross - domain authentication requests sent by vehicles and users, and authenticate the cross - domain authentication requests. After the authentication is passed, it allows vehicles and users to access the requested services;
[0010] Among them, by analyzing the real - time request frequency and the real - time request frequency change rate, it is determined whether there are frequent signature requests and the risk of frequent signature requests, and it is determined whether to pass the authentication based on the verification result and the monitoring result;
[0011] A data sharing module, which is connected to the authentication service module, is used to monitor in real time the cross-domain authentication of identities and service access issued by each vehicle user, determine the frequency of completing cross-domain transmission based on the access records, and adjust the number of node deployments of the blockchain based on the frequency of completing cross-domain transmission.
[0012] Further, the authentication service module includes a sending unit, a receiving unit, a monitoring unit, and a detection unit, where,
[0013] The sending unit is used to enable the sender to sign the message content with its private key to generate a digital signature, and send the message and the digital signature to the receiver;
[0014] The receiving unit is used to verify the digital signature with the public key of the sender to obtain a verification result, including a first verification result and a second verification result;
[0015] The monitoring unit is used to monitor the digital signature process in real time to obtain a monitoring result;
[0016] The detection unit is used to determine whether authentication is passed based on the first verification result and the monitoring result, and determine whether authentication is passed based on the second verification result and biometric verification.
[0017] Further, the verification process of the receiving unit includes,
[0018] Using the public key to decrypt the signature of the received message content to obtain the original message digest;
[0019] Calculating the hash value of the message content based on the original message digest and the hash function to obtain the current information digest;
[0020] Comparing the byte content of the original message digest and the current information digest to obtain a verification result.
[0021] Further, the verification result includes a first verification result and a second verification result, where,
[0022] The first verification result is that the byte content of the original message digest and the current information digest is consistent;
[0023] The second verification result is that the byte content of the original message digest and the current information digest is inconsistent.
[0024] Further, the monitoring unit includes a recording subunit, a first monitoring subunit, and a second monitoring subunit, where,
[0025] The recording subunit is used to record the timestamp, random number, and signature result of each signature;
[0026] The first monitoring subunit is used to determine whether frequent signature requests occur based on the real-time request frequency, and to determine whether there is a risk of frequent signature requests based on the change rate of the real-time request frequency;
[0027] The second monitoring subunit is used to analyze whether the generation pattern of the random number is abnormal.
[0028] Further, the first monitoring subunit determining whether frequent signature requests occur based on the real-time request frequency includes,
[0029] Analyze the timestamps of signature requests in a standard monitoring period;
[0030] Calculate the number of signature requests within the standard monitoring period based on the timestamps to obtain the real-time request frequency;
[0031] Compare the real-time request frequency with the signature request threshold,
[0032] When the real-time request frequency is greater than the signature request threshold, determine that frequent signature requests occur;
[0033] When the real-time request frequency is less than or equal to the signature request threshold, determine whether there is a risk of frequent signature requests based on the change rate of the real-time request frequency.
[0034] Further, the first monitoring subunit determining whether there is a risk of frequent signature requests based on the change rate of the real-time request frequency includes,
[0035] Draw a curve of the real-time request frequency changing with unit time;
[0036] Obtain the slope of the change curve to get the change rate of the real-time request frequency;
[0037] Compare the change rate of the real-time request frequency with the standard request frequency change rate,
[0038] When the change rate of the real-time request frequency is greater than the standard request frequency change rate, determine the risk of frequent signature requests;
[0039] When the change rate of the real-time request frequency is less than or equal to the standard request frequency change rate, determine that there is no risk of frequent signature requests.
[0040] Further, determining whether authentication is passed based on the second verification result and biometric verification includes,
[0041] Collect the biometric characteristics of the user and compare them with the information stored in the identity management module,
[0042] If the biometric characteristics match, pass the authentication and allow access;
[0043] If the biometric characteristics do not match, deny access;
[0044] Among them, biometric features include fingerprint information and voice information.
[0045] Furthermore, determining the frequency of cross-domain transmission based on access records includes
[0046] obtaining the time period between the request initiation time and the completion time;
[0047] dividing the time period into time windows of a fixed length;
[0048] for each time window, determining the access pattern based on the total number of cross-domain transmissions and the standard number of cross-domain transmissions, including the first access pattern and the second access pattern;
[0049] in the first access pattern, calculating the frequency of cross-domain transmission;
[0050] Among them, the frequency of cross-domain transmission is the ratio of the number of cross-domain transmissions of the user within the time window to the length of the time window. The first access pattern is the high-frequency access pattern, and the second access pattern is the low-frequency access pattern.
[0051] Furthermore, adjusting the number of node deployments of the blockchain based on the frequency of cross-domain transmission includes
[0052] when the frequency of cross-domain transmission is greater than the frequency threshold, increasing the number of blockchain node deployments;
[0053] when the frequency of cross-domain transmission is less than or equal to the frequency threshold, reducing the number of blockchain node deployments.
[0054] Compared with the prior art, the beneficial effects of the present invention are as follows. By adopting a cryptography hash algorithm with strong anti-collision performance and utilizing the distributed structure and consensus mechanism of the blockchain, it can effectively resist collision attacks, ensure the security of the system and the integrity of data. When a vehicle conducts cross-domain authentication, it will use its private key to sign the sent information. This signature is a unique identifier generated based on the vehicle's private key and the message content, with non-repudiation and uniqueness. After receiving the information, the receiving party can use the public key of the sending party to verify the signature, thereby confirming the legitimacy of the information source. Since the existence of anti-dictionary attack and anti-brute-force attack has no impact on the validity of the signature result, therefore, when the signature request verification passes, the monitoring unit further monitors the signature request frequency and random number generation pattern in real time, discovers and warns of frequent signature requests and abnormal random number generation in a timely manner, prevents the leakage of the private key and signature forgery. Biometric verification can effectively prevent illegal access to the vehicle networking system, further improving the security of the system. Through real-time monitoring and dynamic adjustment, it ensures the stability and efficiency of the system in high-concurrency scenarios. Using blockchain technology to achieve cross-domain identity authentication supports interoperability and data sharing between different trust domains. Vehicle users only need to send the previously obtained credentials to complete cross-domain authentication, simplifying the authentication process.
[0055] Furthermore, by combining digital signature verification and biometric verification, the security of the system can be effectively improved. In the case of failed digital signature verification, biometric verification provides an additional means of identity confirmation to ensure that only legitimate users can access the system.
[0056] Furthermore, after processing the original message digest through a hash function to obtain the current message digest, the decrypted digest is compared byte by byte with the calculated digest. If the byte contents of both are exactly the same, it indicates that the byte contents of the original message digest and the current message digest are consistent. At this time, it is possible that the message has not been tampered with and the signature is valid. However, if there are anti-dictionary attack and anti-brute-force attack, the attack principles of dictionary attack and brute-force attack are both to try all combinations of passwords. Assume that A has cracked the login passwords of the user and the vehicle through some attack means, that is, can successfully crack the private key of the sending party, thereby forging signatures to make the signatures of any message look valid. Therefore, the monitoring unit monitors the digital signature process to determine whether there is a situation of frequent signatures, so as to judge whether there is a situation and risk that the attacker cracks the private key; if the byte contents of both are inconsistent, it is determined that the byte contents of the original message digest and the current message digest are inconsistent. In this case, biometrics is used for comparison to determine whether the access is normal. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 It is a schematic structural diagram of the cross-domain identity authentication system for vehicle networking based on blockchain in an embodiment of the present invention;
[0058] Figure 2 It is a schematic structural diagram of the authentication service module in an embodiment of the present invention;
[0059] Figure 3 It is a schematic structural diagram of the monitoring unit in an embodiment of the present invention;
[0060] Figure 4 It is a schematic flowchart for determining whether a frequent signature request occurs based on the real-time request frequency in an embodiment of the present invention. Detailed implementation manners
[0061] In order to make the objectives and advantages of the present invention more clear and understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0062] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.
[0063] It should be noted that in the description of the present invention, the terms indicating directions or positional relationships such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the directions or positional relationships shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention.
[0064] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0065] Please refer to Figure 1 as shown, which is a schematic structural diagram of a vehicle networking identity cross-domain authentication system based on blockchain in an embodiment of the present invention. The present invention provides a vehicle networking identity cross-domain authentication system based on blockchain, including,
[0066] An identity management module, which is used to store and manage the identity information of vehicles and users, including vehicle identifiers, user information, and certificates;
[0067] A blockchain network module, which is used to store the identity identifiers of each vehicle and user in the form of blockchain certificates, and store access records on the blockchain;
[0068] An authentication service module, which is used to receive cross-domain authentication requests sent by vehicles and users, and authenticate the cross-domain authentication requests. After successful authentication, vehicles and users are allowed to access the requested services;
[0069] A data sharing module, which is connected to the authentication service module, used to monitor the identity cross-domain authentication and service access situations of each vehicle user in real time, determine the frequency of cross-domain transmission based on access records, and adjust the number of blockchain node deployments according to the frequency of cross-domain transmission.
[0070] In this embodiment, by establishing a decentralized blockchain network, all participants (such as vehicles, service providers, users, etc.) can interact in this network. Vehicle manufacturers register the identity information of new vehicles on the blockchain, including vehicle identification numbers (VINs), manufacturer information, owner information, etc.
[0071] By adopting a strongly collision-resistant cryptographic hash algorithm and utilizing the distributed structure and consensus mechanism of the blockchain, it can effectively resist collision attacks, ensure the security of the system and the integrity of data. When a vehicle conducts cross-domain authentication, it will use its private key to sign the sent information. This signature is a unique identifier generated based on the vehicle's private key and the message content, with non-repudiation and uniqueness. After receiving the information, the receiving party can use the sender's public key to verify the signature, thereby confirming the legality of the information source. Since the existence of anti-dictionary attack and anti-brute-force attack has no impact on the validity of the signature result, therefore, when the signature request verification passes, further monitor the signature request frequency and random number generation pattern in real time through the monitoring unit, timely detect and warn of frequent signature requests and abnormal random number generation, prevent private key leakage and signature forgery. Biometric authentication can effectively prevent illegal access to the vehicle networking system, further improving the security of the system. Through real-time monitoring and dynamic adjustment, ensure the stability and efficiency of the system in high-concurrency scenarios. Use blockchain technology to achieve cross-domain identity authentication, support interoperability and data sharing between different trust domains. Vehicle users only need to send the previously obtained credentials to complete cross-domain authentication, simplifying the authentication process.
[0072] Refer to Figure 2 shown, which is a schematic structural diagram of the authentication service module of the embodiment of the present invention;
[0073] Specifically, the authentication service module includes a sending unit, a receiving unit, a monitoring unit, and a detection unit, where
[0074] The sending unit is used to enable the sender to sign the message content with its private key to generate a digital signature, and send the message and the digital signature to the receiver;
[0075] The receiving unit is used to verify the digital signature with the public key of the sender to obtain a verification result, including a first verification result and a second verification result;
[0076] The monitoring unit is used to monitor the digital signature process in real time to obtain a monitoring result;
[0077] The detection unit is used to determine whether authentication is passed based on the first verification result and the monitoring result, and determine whether authentication is passed based on the second verification result and biometric verification.
[0078] In this embodiment, the system consists of a traffic control center, roadside units, vehicle users, and a blockchain network. Through vehicle registration and credential feedback, that is, when the vehicle is registered, the roadside unit feeds back the identification information of the vehicle to the vehicle user in the form of a credential. When the user's vehicle enters a new roadside unit, identity authentication is required. The vehicle only needs to send the previously obtained credential and can obtain the required information after successful authentication. When the vehicle enters the domain of the roadside unit, the roadside unit will immediately lock the vehicle, that is, record the driving status of all vehicles entering the domain in real time. If a vehicle has a violation or an accident, the roadside unit will immediately obtain the information of the violating vehicle and record it; if it is necessary to obtain the information of the vehicles in the roadside unit domain, the new roadside unit will authenticate the vehicle and the user to obtain the required information. For example, after the vehicle is successfully authenticated for the first time, it will feedback an identifier containing the vehicle user information. By encrypting the vehicle identification information with the public key of the new roadside unit, a ciphertext is generated and sent to the new roadside unit. After receiving the ciphertext, the new roadside unit decrypts the ciphertext with its private key and verifies the validity of the ciphertext. If the verification is successful, the new roadside unit generates a message request, signs the request with its private key to generate a signature, and then sends it to the roadside unit. When the roadside unit receives the signature from the new roadside unit, it verifies the signature with the public key of the new roadside unit. If the verification is successful, the roadside unit will obtain the information of the vehicles in its domain and generate information. The roadside unit signs the information with its own private key to generate a signature and sends it back to the new roadside unit. The signature received by the new roadside unit is verified with the public key of the roadside unit. If the verification is successful, the new roadside unit sends the extracted information to the vehicle user.
[0079] By combining digital signature verification and biometric verification, the security of the system can be effectively improved. In the case of failed digital signature verification, biometric verification provides an additional means of identity confirmation to ensure that only legitimate users can access the system.
[0080] Specifically, the verification process of the receiving unit includes
[0081] using the public key to decrypt the signature of the received message content to obtain the original message digest;
[0082] calculating the hash value of the message content based on the original message digest and the hash function to obtain the current information digest;
[0083] comparing the byte content of the original message digest and the current information digest to obtain the verification result.
[0084] The current information digest is obtained by processing the original message digest through the hash function, so as to compare the decrypted digest with the calculated digest byte by byte. If the byte content of both is exactly the same, it indicates that the byte content of the original message digest and the current information digest is consistent. At this time, it is possible that the message has not been tampered with and the signature is valid. However, if there are anti-dictionary attack and anti-brute-force attack, the attack principles of dictionary attack and brute-force attack are both to try all combination passwords. Suppose A has cracked the login passwords of the user and the vehicle through some attack means, that is, can successfully crack the private key of the sender, thus forging the signature, making the signature of any message look valid. Therefore, the monitoring unit monitors the digital signature process to determine whether there is a situation of frequent signatures, so as to judge whether there is a situation and risk that the attacker cracks the private key; if the byte content of both is inconsistent, it is determined that the byte content of the original message digest and the current information digest is inconsistent. In this case, biometrics is used for comparison to determine whether the access is normal.
[0085] Specifically, the verification result includes a first verification result and a second verification result, where
[0086] the first verification result is that the byte content of the original message digest and the current information digest is consistent;
[0087] the second verification result is that the byte content of the original message digest and the current information digest is inconsistent.
[0088] Refer to Figure 3 shown, which is a schematic structural diagram of the monitoring unit according to an embodiment of the present invention;
[0089] Specifically, the monitoring unit includes a recording subunit, a first monitoring subunit and a second monitoring subunit, where
[0090] the recording subunit is used to record the timestamp, random number and signature result of each signature;
[0091] the first monitoring subunit is used to determine whether there is a frequent signature request based on the real-time request frequency, and determine whether there is a risk of frequent signature request based on the change rate of the real-time request frequency;
[0092] The second monitoring subunit is used to analyze whether the generation pattern of the random number is abnormal.
[0093] In this embodiment, pattern recognition technology is used to detect whether there are predictable or repeating patterns in the random number sequence. Duplicate value detection is to check whether there are duplicate values in the random number sequence. An abnormal pattern is that the same random number appears multiple times in a short period. Periodicity detection is to use Fourier transform or autocorrelation analysis to check whether there is periodicity in the random number sequence, and an abnormal pattern is that the random number sequence exhibits obvious periodicity.
[0094] Refer to Figure 4 As shown, it is a schematic flowchart of the process for determining whether a frequent signature request occurs based on the real-time request frequency in an embodiment of the present invention;
[0095] Specifically, the first monitoring subunit determining whether a frequent signature request occurs based on the real-time request frequency includes
[0096] Step S101, analyzing the timestamps of the signature requests with a standard monitoring period;
[0097] Step S102, calculating the number of signature requests within the standard monitoring period based on the timestamps to obtain the real-time request frequency;
[0098] Step S103, comparing the real-time request frequency with the signature request threshold, and determining whether a frequent signature request occurs based on the comparison result;
[0099] In the case where the real-time request frequency is greater than the signature request threshold, it is determined that a frequent signature request occurs;
[0100] In the case where the real-time request frequency is less than or equal to the signature request threshold, it is determined whether there is a risk of frequent signature requests based on the change rate of the real-time request frequency.
[0101] In this embodiment, the standard monitoring period is set to 1 minute, and the signature request threshold is set to 5 times, indicating that if the number of signature requests exceeds the set threshold within a short period, it is considered that there is an attack. At the same time, by analyzing the degree of change in the request frequency per unit time, it is determined whether there is a risk of frequent signature requests. If the risk of frequent signature requests is detected, the alarm module triggers an alarm to notify the system administrator for further investigation, improving the timeliness of early warning.
[0102] Specifically, the first monitoring subunit determining whether there is a risk of frequent signature requests based on the change rate of the real-time request frequency includes
[0103] Drawing a curve of the real-time request frequency changing with the unit time;
[0104] Obtain the slope of the change curve to get the real-time request frequency change rate;
[0105] Compare the real-time request frequency change rate with the standard request frequency change rate.
[0106] When the real-time request frequency change rate is greater than the standard request frequency change rate, determine that there is a risk of frequent signature requests.
[0107] When the real-time request frequency change rate is less than or equal to the standard request frequency change rate, determine that there is no risk of frequent signature requests.
[0108] In this embodiment, the standard request frequency change rate is the warning threshold of the preset request frequency growth rate, which is used to measure the abnormality of the request volume growth per unit time. It is used to identify whether there is a risk pattern of accelerated growth by monitoring the slope change of the request frequency curve. The set standard request frequency change rate is 2 times per minute. For example, in the current monitoring period, the request volume in the first minute is 3 times, the request volume in the second minute is 5 times, and the request volume in the third minute is 7 times. Then the change rate is an increase of 2 times per minute, and the real-time request frequency change rate is 2 times per minute, without triggering an alarm.
[0109] By monitoring the real-time request frequency change rate, it is possible to prevent a "slow start attack" - an attacker initially maintains a low request volume to avoid threshold detection and then suddenly accelerates to break through the defense. For example, in a credit card signature service, a normal user will not suddenly increase from 2 requests to 8 requests within 1 minute. Such a mutation indicates an attack behavior. Specifically, determining whether to pass authentication based on the second verification result and biometric verification includes
[0110] Collect the biometric characteristics of the user and compare them with the information stored in the identity management module.
[0111] If the biometric characteristics match, pass authentication and allow access;
[0112] If the biometric characteristics do not match, deny access;
[0113] Among them, the biometric characteristics include fingerprint information and voice information.
[0114] In this embodiment, biometric matching is a process of comparing the biometric characteristics with the biometric template pre-stored in the system to determine whether the two belong to the same biological individual; when an attacker tries to access the system with the cracked password, the mobile device screen in the vehicle will present the fingerprint information F of A, and the sound collection device will record the voice information V and compare it with the original information in the vehicle networking system. Therefore, A cannot illegally access the vehicle networking system only relying on these two attack methods, effectively preventing dictionary attacks and brute force cracking attacks.
[0115] Specifically, determining the frequency of completing cross - domain transmission based on access records includes
[0116] obtaining the time period between the request initiation time and the completion time;
[0117] dividing the time period into time windows of a fixed length;
[0118] For each time window, determining the access pattern based on the total number of cross - domain transmissions and the standard number of cross - domain transmissions, including the first access pattern and the second access pattern;
[0119] In the first access pattern, calculating the frequency of completing cross - domain transmission;
[0120] wherein, the frequency of completing cross - domain transmission is the ratio of the number of cross - domain transmissions of the user within the time window to the length of the time window. The first access pattern is a high - frequency access pattern, and the second access pattern is a low - frequency access pattern.
[0121] The time window in this embodiment can be every hour, every day, or every week.
[0122] Specifically, adjusting the number of node deployments of the blockchain based on the frequency of completing cross - domain transmission includes
[0123] when the frequency of completing cross - domain transmission is greater than the frequency threshold, increasing the number of deployed blockchain nodes;
[0124] when the frequency of completing cross - domain transmission is less than or equal to the frequency threshold, reducing the number of deployed blockchain nodes.
[0125] In this embodiment, the frequency threshold for the time window of every hour is 10 times / hour. The formula for increasing the number of deployed blockchain nodes is new node number = current node number × (frequency of completing cross - domain transmission / frequency threshold), rounded up; the formula for reducing the number of deployed blockchain nodes is new node number = current node number × (frequency of completing cross - domain transmission / frequency threshold), rounded down, but not less than the minimum value. For example, if the current number of nodes is 5 and the frequency of completing cross - domain transmission is 15 times / hour (exceeding the threshold by 50%), then the new node number = 5×15 / 10 = 7.5, rounded up to 8 nodes; if the current number of nodes is 5 and the frequency of completing cross - domain transmission is 8 times / hour (20% lower than the threshold), then the new node number = 5×8 / 10 = 4, directly adjusted to 4 nodes (not less than the minimum value of 3).
[0126] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, those skilled in the art can easily understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
[0127] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A blockchain-based cross-domain vehicle network identity authentication system, characterized in that: include, An identity management module, which is used to store and manage the identity information of vehicles and users; A blockchain network module, which is connected to the identity management module and is used to store the identity identifiers of each vehicle and user in the form of blockchain certificates, and to store access records on the blockchain; An authentication service module, which is used to receive cross-domain authentication requests from vehicles and users, and authenticate the cross-domain authentication requests. After the authentication is passed, the vehicle and the user are allowed to access the requested service; Among them, by analyzing the real-time request frequency and the real-time request frequency change rate, it is determined whether frequent signature requests and frequent signature request risks occur, and whether the authentication is passed based on the verification results and monitoring results; A data sharing module is connected to the blockchain network module and the authentication service module to monitor the cross-domain identity authentication and service access status issued by each vehicle user in real time, determine the frequency of completing cross-domain transmission based on the access record, and adjust the number of node deployments of the blockchain based on the frequency of completing cross-domain transmission, including: When the frequency of completing cross-domain transmission is greater than the frequency threshold, increase the number of blockchain nodes deployed; When the frequency of completing cross-domain transmission is less than or equal to the frequency threshold, reduce the number of blockchain nodes deployed; The authentication service module includes a sending unit, a receiving unit, a monitoring unit and a detection unit, wherein: The sending unit is used to enable the sender to sign the message content using its private key, generate a digital signature, and send the message and the digital signature to the recipient; The receiving unit is used to verify the digital signature using the public key of the sender to obtain a verification result, including a first verification result and a second verification result; The monitoring unit is used to monitor the digital signature process in real time and obtain monitoring results; The detection unit is used to determine whether the authentication is passed based on the first verification result and the monitoring result, and to determine whether the authentication is passed based on the second verification result and the biometric verification.
2. The blockchain-based Internet of Vehicles identity cross-domain authentication system according to claim 1 is characterized in that: The verification process of the receiving unit includes: Use the public key to decrypt the signature of the received message content to obtain the original message digest; Calculate the hash value of the message content based on the original message digest and the hash function to obtain the current message digest; Compare the byte contents of the original message digest and the current message digest to obtain the verification result.
3. The blockchain-based cross-domain vehicle network identity authentication system according to claim 2 is characterized in that: The verification result includes a first verification result and a second verification result, wherein: The first verification result is that the byte contents of the original message digest and the current message digest are consistent; The second verification result is that the byte contents of the original message digest and the current message digest are inconsistent.
4. The blockchain-based cross-domain vehicle network identity authentication system according to claim 3 is characterized in that: The monitoring unit includes a recording subunit, a first monitoring subunit and a second monitoring subunit, wherein: The recording subunit is used to record the timestamp, random number and signature result of each signature; The first monitoring subunit is used to determine whether frequent signature requests occur based on the real-time request frequency, and determine whether frequent signature request risks occur based on the real-time request frequency change rate; The second monitoring subunit is used to analyze whether the generation mode of the random number is abnormal.
5. The blockchain-based cross-domain vehicle network identity authentication system according to claim 4 is characterized in that: The first monitoring subunit determines whether frequent signature requests occur based on the real-time request frequency, including: Analyze the timestamps of signature requests at standard monitoring periods; Calculate the number of signature requests within the standard monitoring period based on the timestamp to obtain the real-time request frequency; Compare the real-time request frequency with the signature request threshold, When the real-time request frequency is greater than the signature request threshold, it is determined that frequent signature requests occur; When the real-time request frequency is less than or equal to the signature request threshold, whether a frequent signature request risk occurs is determined based on the real-time request frequency change rate.
6. The blockchain-based cross-domain vehicle network identity authentication system according to claim 5 is characterized in that: The first monitoring subunit determines whether there is a risk of frequent signature requests based on the real-time request frequency change rate, including: Draw a curve of real-time request frequency versus unit time; Get the slope of the change curve and obtain the real-time request frequency change rate; Compare the real-time request frequency change rate with the standard request frequency change rate, When the real-time request frequency change rate is greater than the standard request frequency change rate, it is determined that there is a risk of frequent signature requests; When the real-time request frequency change rate is less than or equal to the standard request frequency change rate, it is determined that there is no risk of frequent signature requests.
7. The blockchain-based Internet of Vehicles identity cross-domain authentication system according to claim 1 is characterized in that: Determining whether authentication is successful based on the second verification result and the biometric verification includes, Collect the user's biometrics and compare them with the information stored in the identity management module. If the biometrics match, authentication is passed and access is allowed; If the biometrics do not match, access is denied; Among them, biometrics include fingerprint information and voice information.
8. The blockchain-based Internet of Vehicles identity cross-domain authentication system according to claim 1 is characterized in that: The frequency of completing cross-domain transfers based on access records includes: Get the time period between the request initiation time and the completion time; Divide the period into time windows of fixed length; For each time window, determining an access mode based on a total cross-domain transmission number and a standard cross-domain transmission number, including a first access mode and a second access mode; In the first access mode, the frequency of completing the cross-domain transmission is calculated; The frequency of completing cross-domain transmission is the ratio of the number of cross-domain transmissions of the user within the time window to the length of the time window. The first access mode is a high-frequency access mode, and the second access mode is a low-frequency access mode.
Citation Information
Patent Citations
Lightweight cross-domain identity authentication method and system in Internet of Vehicles environment
CN119364359A
Internet of Things (IoT) cross-domain authentication system and method based on block chain
CN108737370A
Copyright registration method and device based on block chain and terminal equipment
CN109684786A