A UAV-assisted vehicle cross-domain authentication method and system based on digital certificates
Through the cross-domain authentication method of drone-assisted vehicles based on digital certificates, the control center generates system parameters and authentication certificates, combined with hidden identity lists and batch verification, the information leakage problem in cross-domain interaction of vehicles in rural or mountainous areas is solved, real-time monitoring and secure communication are realized.
Patent Information
- Application Number
- CN202510034239.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-01-09
AI Technical Summary
In rural areas or mountainous areas, information is easily stolen when vehicles interact across domains, vehicle identity privacy is easily leaked, and prior art is difficult to efficiently protect privacy and reduce communication and computing overhead.
The cross-domain authentication method of drone-assisted vehicles is adopted based on digital certificates. System parameters and authentication certificates are generated through the control center, combined with hidden identity lists and batch verification mechanisms, to ensure the undeniability and integrity of communication and protect vehicle privacy.
Real-time monitoring and analysis of complex terrain is realized, communication security is enhanced, single point of failure risk is reduced, authentication efficiency and reliability are improved, and vehicle privacy is protected.
Smart Images

Figure CN119906546B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of privacy protection, and particularly to a method and system for cross-domain authentication of drones-assisted vehicles based on digital certificates. Background Art
[0002] With the development of Internet technology, the Internet of Vehicles (IoV), as an Internet-based intelligent transportation system, connects various elements such as vehicles, roads, and traffic facilities to achieve information interaction and collaboration among vehicles, between vehicles and roads, and between vehicles and traffic facilities, thereby improving traffic efficiency, reducing the accident rate, and improving the traffic environment. However, road traffic management in rural or mountainous areas has always faced many challenges, including complex terrain and landforms, changing weather conditions, and traffic safety hazards. Therefore, to solve the problems of insufficient base station coverage and untimely rescue in rural or mountainous areas, it is a current trend to apply drones to the IoV. Due to its flight ability, the drone is not restricted by the physical structure of the road and can move freely to support the required network. Moreover, it can reduce the number of deployed infrastructure nodes, thereby reducing the deployment cost.
[0003] Secondly, when a vehicle moves over a long distance in a rural or mountainous area, it needs to interact across domains with vehicles in other regions. During the interaction process, information is easily stolen, and the vehicle identity privacy is also easily leaked. Therefore, a security mechanism of digital certificates is adopted to prevent information leakage. These certificates are usually issued by a control center and contain the public keys and identity information of vehicles or drones, ensuring the legality of both communication parties and the authenticity of identities. However, the signature mechanism in the certificate further enhances security, making any unauthorized tampering result in verification failure, thus providing non-repudiation and integrity guarantees for communication. In addition, the use of digital certificates combined with a hidden identity list can perform effective authentication without revealing the true identity of the vehicle, thereby protecting the privacy of users and ensuring the credibility and stability of the IoV system. By establishing a secure connection between drones and vehicles through the combination of drones and digital certificates, the data privacy between drones and vehicle users is guaranteed. However, in existing technologies, many solutions have been proposed for privacy protection, but how to efficiently protect privacy and reduce communication and computing overhead resources remains a problem. Summary of the Invention
[0004] To solve the technical problems in the above background, the present invention provides a method for cross-domain authentication of drones-assisted vehicles based on digital certificates. The steps include:
[0005] Generate system parameters based on a control center;
[0006] Generate authentication certificates for vehicles or drones based on the system parameters;
[0007] When a vehicle accesses services in different drone jurisdictions, the authentication certificate is used to complete cross-domain authentication.
[0008] Preferably, the method for initializing the control center includes: selecting a prime number q, and selecting G1 and G2 as groups of prime order q; selecting P as a generator of G1, representing a bilinear mapping; the control center selects As the system private key, and calculate the corresponding public key, where PK pub =s·P; In addition, the control center selects h1: {0, 1}* → G1 and publicly provide {G1,G2,P,PK pub ,h1}, h1 represents the cryptographic hash function.
[0009] Preferably, the method for generating an authentication certificate for a vehicle or drone includes:
[0010] The vehicle or drone first randomly generates its own private key and calculates the corresponding public key through the parameters generated by the control center;
[0011] Submit identity information, public key and certificate validity period to the control center;
[0012] Use the control center's private key and a predefined cryptographic hash function to sign the information provided by the vehicle or drone to generate a unique digital signature;
[0013] The control center integrates the identity information, public key, certificate validity period and digital signature to generate a complete certificate and returns it to the vehicle or drone.
[0014] Preferably, the cross-domain authentication includes two stages: cross-domain information request and cross-domain information response;
[0015] Cross-domain information request: When a vehicle accesses a service in another drone’s jurisdiction, it initiates a request to the target drone through the local drone. The vehicle first generates a signature, which contains the vehicle’s identity information, request content, and timestamp to ensure the authenticity and timeliness of the request. The vehicle packages the request information, signature, and its own certificate into a message and forwards it to the target drone through the local drone. After receiving the request, the target drone will verify the legitimacy of the message in the cross-domain information response phase to ensure the credibility of the vehicle’s identity and request content.
[0016] Cross - domain information response; the target UAV verifies the cross - domain request from the vehicle. First, it checks whether the timestamp of the request is valid; then, using the certificate revocation list provided by the control center, it confirms whether the vehicle's certificate is still valid; if the certificate is not revoked, the target UAV verifies the vehicle's signature; after successful verification, the target UAV obtains the hidden identity list from the control center and assigns it to the vehicle, and the vehicle will verify the validity of the message again after receiving it; when all verifications are passed, the vehicle will be able to use the services provided by the target UAV.
[0017] The present invention also provides a UAV - assisted vehicle cross - domain authentication system based on digital certificates. The system is used to implement the above - mentioned method and includes: an initialization module, a generation module, and an authentication module;
[0018] The initialization module is used to generate system parameters based on the control center;
[0019] The generation module is used to generate authentication certificates for vehicles or UAVs based on the system parameters;
[0020] When a vehicle accesses services in different UAV jurisdiction areas, the authentication module uses the authentication certificate to complete cross - domain authentication.
[0021] Preferably, the working process of the initialization module includes: selecting a prime number q, and selecting G1 and G2 as groups of prime order q; selecting P as the generator of G1, representing a bilinear mapping; the control center selects as the system private key, and calculates the corresponding public key, where PK pub = s·P; in addition, the control center selects h1|{0,1} * →G1 and publicly provides {G1, G2, P, PK pub , h1}, where h1 represents an encryption hash function.
[0022] Preferably, the working process of the generation module includes:
[0023] First, randomly generate its own private key for the vehicle or UAV, and calculate the corresponding public key through the generation parameters of the control center;
[0024] Submit the identity information, public key, and certificate validity period to the control center;
[0025] Use the private key of the control center and a predefined encryption hash function to sign the information provided by the vehicle or UAV, generating a unique digital signature;
[0026] The control center integrates the identity information, public key, certificate validity period, and digital signature together to generate a complete certificate and return it to the vehicle or UAV.
[0027] Preferably, cross - domain authentication includes two stages: cross - domain information request and cross - domain information response;
[0028] Cross - domain information request: When a vehicle accesses services in another UAV jurisdiction area, it initiates a request to the target UAV through the local UAV. The vehicle first generates a signature that includes the vehicle's identity information, request content, and timestamp to ensure the authenticity and timeliness of the request. The vehicle packs the request information, signature, and its own certificate into a message and forwards it to the target UAV through the local UAV. After receiving the request, the target UAV will verify the legality of the message during the cross - domain information response stage to ensure the credibility of the vehicle's identity and request content;
[0029] Cross - domain information response: The target UAV verifies the cross - domain request from the vehicle. First, it checks whether the timestamp of the request is valid. Then, using the certificate revocation list provided by the control center, it confirms whether the vehicle's certificate is still valid. If the certificate has not been revoked, the target UAV will verify the vehicle's signature. After successful verification, the target UAV obtains the hidden identity list from the control center and assigns it to the vehicle. The vehicle will verify the validity of the message again after receiving it. When all verifications pass, the vehicle will be able to use the services provided by the target UAV.
[0030] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0031] 1. The present invention utilizes advanced UAV technology to conduct comprehensive monitoring and analysis of complex road environments, such as rural areas or mountainous areas with complex terrains, to achieve real - time and accurate judgment and support for road conditions, providing important information support for road safety management.
[0032] 2. The present invention proposes an innovative vehicle - to - vehicle ad - hoc network architecture based on digital certificates. The digital certificate provides a mechanism, and the signature mechanism in the certificate further enhances security, making any unauthorized tampering result in verification failure, thus providing non - repudiation and integrity guarantees for communication.
[0033] 3. The multi - control center design in the present invention, through a distributed control center architecture, not only effectively shares the burden of the control center but also solves the single - point failure problem and improves the reliability of the system.
[0034] 4. The present invention uses a hidden identity list, which can perform effective authentication without revealing the vehicle's true identity, thus protecting the privacy of users.
[0035] 5. The present invention uses a batch verification mechanism, which improves the efficiency and reliability of the authentication process. By batch - processing and verifying the authentication requests of multiple vehicles, it optimizes the utilization of system resources and reduces authentication latency. Description of the Drawings
[0036] To more clearly illustrate the technical solution of the present invention, the accompanying drawings required in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0037] Figure 1 It is the entity system diagram of the embodiment of the present invention;
[0038] Figure 2 It is the schematic diagram of the method flow of the embodiment of the present invention;
[0039] Figure 3 It is the process diagram of the digital certificate generation stage of the embodiment of the present invention;
[0040] Figure 4 It is the process diagram of the in-domain information request stage of the embodiment of the present invention;
[0041] Figure 5 It is the process diagram of the cross-domain information response stage of the embodiment of the present invention. Detailed implementation manners
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0043] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0044] Before the description, the important terms and constraints of the present invention will be introduced first:
[0045] The core idea of the bilinear pairing is to establish a mapping relationship between two different group elements, and this mapping satisfies the bilinear property, that is, the multiplication operation of the elements within the group can be transformed into the multiplication operation of the elements outside the group under the pairing operation.
[0046] The RSA (Rivest-Shamir-Adleman) algorithm is mainly used for encryption and decryption, but it can also be used for digital signatures. In RSA signatures, the private key is used to generate signatures, and the public key is used to verify signatures
[0047] As Figure 1 shown, the present invention involves the following four types of entities:
[0048] Control Center (CC): In the vehicle networking, the control center is considered to be completely trustworthy. The control center generates system parameters and generates the public-private key pairs of vehicles.
[0049] Drone: As a mobile roadside unit, the drone has the general characteristics of a roadside unit, can store keys and perform encryption / decryption operations. It is an honest but curious wireless communication device. The drone communicates with vehicles through a wireless channel and communicates with the control center. It is considered to have an ultra-fast transmission speed to support seamless coverage of vehicle communication and provide network access services for vehicles.
[0050] Vehicles: Vehicles are equipped with on-vehicle units for communicating with other entities in the vehicle networking. The on-vehicle units store keys for authentication during cross-domain processes.
[0051] HideIdentityList: The HideIdentityList table is essentially a database containing reusable HideIdentityLists. Each HideIdentityList has an expiration time, and when the HideIdentityList expires, its association with a specific vehicle is revoked and it is set to an available state in the HideIdentityList table.
[0052] Embodiment 1
[0053] As Figure 2 shown, it is a schematic diagram of the method flow of the present invention. The steps include:
[0054] S1. Generate system parameters based on the control center.
[0055] The control center (CC) is a distributed registration center architecture. Entities in each region register with the trustworthy institution CC in their respective regions through a secure channel. Each control center CC at different locations generates a set of local public-private key pairs, as well as system parameters such as group and generator, hash function, and bilinear mapping attributes.
[0056] The method for initializing the control center CC includes: CC selects a prime number q, and selects G1 and G2 as groups of prime order q. Select P as the generator of G1, which represents a bilinear mapping. CC selects as the system private key and calculates the corresponding public key, where PK pub = s·P; in addition, CC selects h1: {0,1} * →G1 and publicly provides {G1, G2, P, K pub , h1}.
[0057] S2. Generate authentication certificates for vehicles or drones based on the system parameters.
[0058] The vehicle or drone first randomly generates its own private key and calculates the corresponding public key using the generation parameters of the control center; they submit the identity information (such as the unique identifier of the vehicle or drone), the public key, and the validity period of the certificate to the control center CC; CC uses its own private key and a predefined cryptographic hash function to sign this information and generate a unique digital signature; CC integrates the identity information, the public key, the certificate validity period, and the digital signature together to generate a complete certificate and returns it to the vehicle or drone.
[0059] S201. Vehicle v i Randomly select a private key and calculate the corresponding public key PK vi = s vi ·P, where P is a predefined generator. CC i Uses the RSA algorithm to calculate the signature for vehicle v i :
[0060]
[0061] In the formula, ID vi represents the identity information of vehicle v i ; EXP vi represents the expiration time of the signature; h1 represents the cryptographic hash function.
[0062] Therefore, CC i generates a certificate for vehicle v i :
[0063]
[0064] S202. Using the same method, CC i registers and generates corresponding certificates for the drones (D) in the area. First, D i randomly selects a private key and calculates the corresponding public key:
[0065] PK di = s di ·P
[0066] where P represents a predefined generator.
[0067] CC i uses the RSA algorithm to calculate the signature for D i :
[0068]
[0069] In the formula, ID di represents the identity information of D i .
[0070] Therefore, CC i is D i generated a certificate:
[0071]
[0072] Finally, CC j uses the same method to generate a certificate for D j The digital certificate generation process is as Figure 3 shown.
[0073] S203. The drone periodically broadcasts service information to the area it is responsible for, such as road information, weather conditions, or other relevant service content; when broadcasting, the drone generates a signature that includes its own identity information, a timestamp, and the content of the broadcast information, and this signature is used to prove the source and authenticity of the information; other drones that receive the broadcast information first check whether the timestamp is within the valid range to confirm whether the information is still valid; by verifying the legality of the signature, it is ensured that the information has not been tampered with and indeed comes from a trusted drone. If the verification is successful, the receiving drone will store its information and further broadcast it within its own service area to remind vehicles or other users to pay attention to relevant service content or road safety.
[0074] Specifically, D j periodically broadcasts service information to D i The signature calculated by D j is:
[0075] Sig dj = s dj ·h1(ID dj ||T dj ||m dj )
[0076] In the formula, m dj represents the information sent by D j to D i ; T dj is the timestamp of the current information transmission.
[0077] Therefore, the information sent by drone D j is:
[0078] {m dj , T dj , ID dj , Sig dj}.
[0079] After D i receives the information published by D j , it performs the following steps:
[0080] First, check the timestamp T dj to see if it is within the valid time range; then, use the public key of D j to verify the signature of the published information, i.e., e(Sig dj , P) = e(h1(ID dj ||T dj ||m dj ), PK dj ). If the verification is successful, D i stores the service information of D j and broadcasts this information within the area of D i to remind drivers and passengers to pay attention to road safety and weather conditions.
[0081] S3. When the vehicle accesses services in different UAV jurisdiction areas, use the authentication certificate to complete cross-domain authentication.
[0082] This step is divided into two phases: namely, cross-domain information request and cross-domain information response.
[0083] (1) Cross-domain information request
[0084] When the vehicle needs to access services in another UAV jurisdiction area, it will initiate a request to the target UAV through the current UAV (local UAV). The vehicle first generates a signature that contains the vehicle's identity information, request content, and timestamp to ensure the authenticity and timeliness of the request; the vehicle packs the request information, signature, and its own certificate into a message and forwards it to the target UAV through the local UAV; after receiving the request, the target UAV will verify the legality of the message in the cross-domain information response phase to ensure the credibility of the vehicle's identity and request content.
[0085] D i broadcasts information within its area. When vehicle v i wants to access services within the area of D j , it needs to send a cross-domain request message to D i through D j . The specific process is as follows:
[0086] Vehicle v i calculates the signature v i and sends a cross-domain request message to D i through D j as shown in In this formula, respectively represent the request information, request timestamp, and the signature of vehicle v i for this specific request. The information request process is as Figure 4 shown.
[0087] (2) Cross - domain Information Response
[0088] The target UAV verifies the cross - domain request from the vehicle. It checks whether the timestamp of the request is valid to ensure that the message has not expired; the target UAV uses the Certificate Revocation List provided by the Control Center (CC) to confirm whether the vehicle's certificate is still valid; if the certificate has not been revoked, the target UAV verifies the vehicle's signature to ensure the integrity and authenticity of the request information;
[0089] After successful verification, the target UAV obtains a Hidden Identity List (HIDL) from the CC and assigns it to the vehicle. This hidden identity list is used to protect the vehicle's privacy while supporting subsequent communication with the target UAV; the target UAV returns a confirmation message containing the hidden identity list to the vehicle through the local UAV, and the vehicle will verify the validity of the message again after receiving it; if all verifications pass, the vehicle will be able to use the services provided by the target UAV.
[0090] Specifically, D j After receiving the request message from vehicle v i , D j verifies the timestamp to check if it is within the valid period; D j retrieves the Certificate Revocation List from CC j to check if the certificate of vehicle v i has been revoked; D j verifies the request message of vehicle v by calculating i . If the equation holds, the verification passes.
[0091] If the verification is successful, CC j provides a Hidden Identity List HIDL for vehicle v i from the hidden identity list table, and this identity will be used for subsequent communication between the vehicle and D j . D j Sends a cross - domain confirmation message to vehicle v i through D i . The confirmation message includes and information containing the anonymous identity
[0092] After vehicle v i receives the confirmation message from D j , it performs the following steps: verifies the validity of the timestamp; v i verifies the confirmation message of D by calculating j . If the equation holds, it indicates that D j has accepted the cross - domain request; finally, v i calculates Information response process Figure 5 shown.
[0093] This embodiment adopts a batch verification method for the target drone to simultaneously process cross-domain requests from multiple vehicles. When multiple vehicles send requests containing signatures, the traditional method needs to verify each signature one by one, which is computationally intensive and inefficient. Batch verification combines multiple signatures to generate an overall verification formula, thereby verifying the legitimacy of all signatures at once.
[0094] Single verification: When the vehicle v i By D i To D j Send signature Sig vi =s vi ·h1(m vi ||T vi ||ID vi ), D j The individual validation calculations performed are as follows:
[0095] e(Sig vi , P)=e(h1(ID vi ||T vi ||m vi ), PK vi )
[0096] If this equation holds true, D j Complete the vehicle v i verification; when m vehicles initiate requests at the same time, m separate verifications are required.
[0097] Batch verification: When D j Receive information m from m different vehicles vk Signature vk =s vk ·h1(m vk ||T vk ||ID vk ), where k = 1, 2...m, D j ; Perform batch verification by calculating:
[0098]
[0099] If this equation holds true, D j Complete batch verification of these m vehicles.
[0100] Embodiment 2
[0101] This embodiment also provides a UAV-assisted vehicle cross-domain authentication system based on digital certificates, including: an initialization module, a generation module, and an authentication module; the initialization module is used to generate system parameters based on a control center; the generation module is used to generate authentication certificates for vehicles or UAVs based on the system parameters; when a vehicle accesses services in different UAV jurisdiction areas, the authentication module uses the authentication certificates to complete cross-domain authentication.
[0102] Next, this embodiment will be used to elaborate in detail on how the present invention solves technical problems in real life.
[0103] First, the initialization module generates system parameters based on the control center.
[0104] The control center (CC) is a distributed registration center architecture. Entities in each area register with a trusted institution CC in their respective areas through a secure channel. Each control center CC at different locations generates a set of local public and private key pairs, as well as system parameters such as groups, generators, hash functions, and bilinear mapping attributes.
[0105] The method for initializing the control center CC includes: CC selects a prime number q, and selects G1 and G2 as groups of prime order q. Select P as the generator of G1, which represents a bilinear mapping. CC selects as the system private key and calculates the corresponding public key, where PK pub = s·P; in addition, CC selects h1: {0, 1} * →G1 and publicly provides {G1, G2, P, PK pub .
[0106] The generation module generates authentication certificates for vehicles or UAVs based on the system parameters.
[0107] Vehicles or UAVs first randomly generate their own private keys and calculate the corresponding public keys through the generation parameters of the control center; they submit identity information (such as the unique identifier of the vehicle or UAV), public keys, and the validity period of the certificate to the control center CC; CC uses its own private key and a predefined cryptographic hash function to sign this information to generate a unique digital signature; CC integrates the identity information, public keys, certificate validity period, and digital signature together to generate a complete certificate and returns it to the vehicle or UAV.
[0108] S201. Vehicle v i Randomly selects a private key and calculates the corresponding public key PK vi = s vi ·P, where P is a predefined generator. CC i Uses the RSA algorithm to calculate the signature for vehicle v i :
[0109]
[0110] Wherein, ID vi represents the identity information of vehicle v i ; EXP vi represents the expiration time of the signature; h1 represents an encryption hash function.
[0111] Therefore, CC i generates a certificate for vehicle v i :
[0112]
[0113] S202. Using the same method, CC i registers and generates corresponding certificates for the drones (D) within the area. First, D i randomly selects a private key and calculates the corresponding public key:
[0114] PK di = s di ·P where P represents a predefined generator.
[0115] CC i uses the RSA algorithm to calculate the signature for D i :
[0116]
[0117] Wherein, ID di represents the identity information of D i .
[0118] Therefore, CC i generates a certificate for D i :
[0119]
[0120] Finally, CC j uses the same method to generate a certificate for D j . The digital certificate generation process is as Figure 3 shown.
[0121] S203. The drone regularly broadcasts service information to the area it is responsible for, such as road information, weather conditions, or other relevant service content; when broadcasting, the drone generates a signature that includes its own identity information, timestamp, and the content of the broadcast information, and this signature is used to prove the source and authenticity of the information; other drones that receive the broadcast information first check whether the timestamp is within the valid range to confirm whether the information is still valid; by verifying the legality of the signature, it is ensured that the information has not been tampered with and indeed comes from a trusted drone. If the verification is successful, the receiving drone will store the information and further broadcast it within its own service area to remind vehicles or other users to pay attention to relevant service content or road safety.
[0122] Specifically, D j Regularly broadcasts to D i Service information. The signature is calculated by D j as follows:
[0123] Sig dj = s dj ·h1(ID dj ||T dj ||m dj )
[0124] Where m dj represents the information sent by D j to D i ; T dj is the timestamp of the current information transmission.
[0125] Therefore, the information sent by drone D j is:
[0126] {m dj , T dj , ID dj , Si gdj}.
[0127] After D i receives the information published by D j , it executes the following process:
[0128] First, check whether the timestamp T dj is within the valid time range; then, use the public key of D j to verify the signature of the published information, that is, e(Sig dj , P) = e(h1(ID dj ||T dj ||m dj ), PK dj ). If the verification is successful, D i stores the service information of D j and broadcasts it within Di Broadcast this information within the area to alert drivers and passengers to road safety and weather conditions.
[0129] The authentication module is used to complete cross-domain authentication using the authentication certificate when the vehicle accesses services in different drone jurisdiction areas.
[0130] This process is divided into two phases: cross-domain information request and cross-domain information response.
[0131] (1) Cross-domain information request
[0132] When the vehicle needs to access services in another drone jurisdiction area, it will initiate a request to the target drone through the currently located drone (local drone). The vehicle first generates a signature that contains the vehicle's identity information, request content, and timestamp to ensure the authenticity and timeliness of the request; the vehicle packs the request information, signature, and its own certificate into a message and forwards it to the target drone through the local drone; after receiving the request, the target drone will verify the legality of the message during the cross-domain information response phase to ensure the credibility of the vehicle identity and request content.
[0133] D i Broadcast information within its area. When vehicle v i wants to access services in area D j it needs to send a cross-domain request message to D through D i to D j The specific process is as follows:
[0134] Vehicle v i calculates the signature v i sends a cross-domain request message to D through D i to D j The cross-domain request message is as follows: In this formula, respectively represent the request information, request timestamp, and the signature of vehicle v i for this specific request. The information request process is as Figure 4 shown.
[0135] (2) Cross-domain information response
[0136] The target drone verifies the cross-domain request from the vehicle. It checks whether the timestamp of the request is valid to ensure that the message has not expired; the target drone uses the certificate revocation list provided by the control center (CC) to confirm whether the vehicle's certificate is still valid; if the certificate has not been revoked, the target drone will verify the vehicle's signature to ensure the integrity and authenticity of the request information;
[0137] After successful verification, the target UAV obtains a Hidden Identity List (HIDL) from the CC and assigns it to the vehicle. This hidden identity list is used to protect the vehicle's privacy while supporting subsequent communication with the target UAV; the target UAV returns a confirmation message containing the hidden identity list to the vehicle via the local UAV, and the vehicle will verify the validity of the message again after receiving it; if all verifications pass, the vehicle will be able to use the services provided by the target UAV.
[0138] Specifically, D j After receiving a request message from vehicle v i , D j verifies whether the timestamp is within the valid period; D j retrieves the Certificate Revocation List from the CC j to check whether the certificate of vehicle v i has been revoked; D j verifies the request message of vehicle v by calculating. If the equation holds, the verification passes. i
[0139] If the verification is successful, the CC j provides a hidden identity list HIDL for vehicle v i from the hidden identity list table, and this identity will be used for subsequent communication between the vehicle and D j . D j Sends a cross-domain confirmation message to vehicle v i through D i . The confirmation message includes and information containing the anonymous identity
[0140] After vehicle v i receives the confirmation message from D j , the following process is executed: verify the validity of the timestamp; v i verifies the confirmation message of D by calculating. If the equation holds, it indicates that D j has accepted the cross-domain request; finally, v j calculates i The information response process is as Figure 5 shown.
[0141] This embodiment adopts a batch verification method for the target UAV to process cross-domain requests of multiple vehicles simultaneously. When multiple vehicles send requests containing signatures, the traditional method needs to verify each signature one by one, with a large computational amount and low efficiency. Batch verification combines multiple signatures to generate an overall verification formula, thereby verifying the legitimacy of all signatures at once.
[0142] Single verification: When the vehicle v i By D i To D j Send signature Sig vi =s vi ·h1(m vi ||T vi ||ID vi ),D j The individual validation calculations performed are as follows:
[0143] e(Sig vi , P)=e(h1(ID vi ||T vi ||m vi ), PK vi ) If this equation holds, D j Complete the vehicle v i verification; when m vehicles initiate requests at the same time, m separate verifications are required.
[0144] Batch verification: When D j Receive information m from m different vehicles vk Signature vk =s vk ·h1(m vk ||T vk ||ID vk ), where k = 1, 2...m, D j ; Perform batch validation by calculating:
[0145]
[0146] If this equation holds true, D j Complete batch verification of these m vehicles.
[0147] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.
Claims
1. A method for cross - domain authentication of drones - assisted vehicles based on digital certificates, characterized in that the steps Including: Based on the control center, generate system parameters; Based on the system parameters, generate an authentication certificate for the vehicle or the drone; When the vehicle accesses services in different drone jurisdiction areas, use the authentication certificate to complete cross-domain authentication; Cross-domain authentication includes two stages: cross-domain information request and cross-domain information response; Cross-domain information request; when the vehicle accesses services in another drone jurisdiction area, initiate a request to the target drone through the local drone; The vehicle first generates a signature that contains the vehicle's identity information, request content, and timestamp to ensure the authenticity and timeliness of the request; The vehicle packs the request information, signature, and its own certificate into a message and forwards it to the target drone through the local drone; after receiving the request, the target drone will verify the legality of the message in the cross-domain information response stage to ensure the credibility of the vehicle identity and request content; Cross-domain information response; the target drone verifies the cross-domain request from the vehicle. First, it checks whether the timestamp of the request is valid; then, it uses the certificate revocation list provided by the control center to confirm whether the vehicle's certificate is still valid; If the certificate has not been revoked, the target drone will verify the vehicle's signature; after successful verification, the target drone obtains the hidden identity list from the control center and assigns it to the vehicle. After receiving it, the vehicle will verify the validity of the message again; when all verifications are passed, the vehicle will be able to use the services provided by the target drone.
2. The method for cross - domain authentication of drones - assisted vehicles based on digital certificates according to claim 1, wherein, The method for initializing the control center includes: selecting a prime number q, and selecting G1 and G2 as groups of prime order q; selecting P as the generator of G1, representing a bilinear mapping; the control center selects as the system private key and calculates the corresponding public key, where PK pub = s·P; in addition, the control center selects h1: {0, 1} * → G1 and publicly provides {G1, G2, P, PK pub , h1}, where h1 represents an encryption hash function.
3. The method for cross - domain authentication of drones - assisted vehicles based on digital certificates according to claim 1, wherein, The method for generating an authentication certificate for a vehicle or a drone includes: The vehicle or the drone first randomly generates its own private key and calculates the corresponding public key through the generation parameters of the control center; Submit the identity information, public key, and certificate validity period to the control center; Use the private key of the control center and a predefined cryptographic hash function to sign the information provided by the vehicle or the drone to generate a unique digital signature; The control center integrates the identity information, public key, certificate validity period, and digital signature to generate a complete certificate and returns it to the vehicle or the drone.
4. A UAV-assisted vehicle cross-domain authentication system based on digital certificates, the system is used to implement the method described in any one of claims 1-3, characterized in that, Including: Initialization module, generation module, and authentication module; The initialization module is used to generate system parameters based on the control center; The generation module is used to generate an authentication certificate for the vehicle or the drone based on the system parameters; The authentication module, when the vehicle accesses services in different drone jurisdiction areas, uses the authentication certificate to complete cross-domain authentication; Cross-domain authentication includes two stages: cross-domain information request and cross-domain information response; Cross-domain information request; when the vehicle accesses services in another drone jurisdiction area, initiate a request to the target drone through the local drone; The vehicle first generates a signature that contains the vehicle's identity information, request content, and timestamp to ensure the authenticity and timeliness of the request; The vehicle packs the request information, signature, and its own certificate into a message and forwards it to the target drone through the local drone; after receiving the request, the target drone will verify the legality of the message in the cross-domain information response stage to ensure the credibility of the vehicle identity and request content; Cross-domain information response; the target UAV verifies the cross-domain request from the vehicle. First, it checks whether the timestamp of the request is valid; then, using the certificate revocation list provided by the control center, it confirms whether the vehicle's certificate is still valid. If the certificate has not been revoked, the target UAV will verify the vehicle's signature; after successful verification, the target UAV obtains the hidden identity list from the control center and assigns it to the vehicle. After receiving it, the vehicle will verify the validity of the message again; when all verifications are passed, the vehicle will be able to use the services provided by the target UAV.
5. The drone-assisted vehicle cross-domain authentication system based on digital certificates according to claim 4, characterized in that, The working process of the initialization module includes: selecting a prime number q, and selecting G1 and G2 as groups of prime order q; selecting P as the generator of G1, representing a bilinear mapping; the control center selects as the system private key, and calculates the corresponding public key, where PK pub = s·P; in addition, the control center selects h1: {0, 1} * → G1 and publicly provides {G1, G2, P, PK pub , h1}, h1 represents an encryption hash function.
6. The drone-assisted vehicle cross-domain authentication system based on digital certificates according to claim 4, wherein The working process of the generation module includes: Randomly generate its own private key for the vehicle or UAV first, and calculate the corresponding public key through the generation parameters of the control center; Submit the identity information, public key, and certificate validity period to the control center; Use the private key of the control center and a predefined cryptographic hash function to sign the information provided by the vehicle or UAV, generating a unique digital signature; The control center integrates the identity information, public key, certificate validity period, and digital signature together to generate a complete certificate and return it to the vehicle or UAV.
Citation Information
Patent Citations
Cross-domain anonymous authentication method and system based on block chain
CN112039872A
Cross-domain identity authentication method, system and equipment based on block chain
CN115378681A