Lightweight Internet of Vehicles hierarchical block chain privacy protection method
By adopting a hierarchical blockchain network model and edge blockchain architecture in the edge computing scenario of the Internet of Vehicles, combined with dynamic vehicle credentials and attribute encryption technology, the problem of user and data privacy leakage in the Internet of Vehicles is solved, and efficient privacy protection and security enhancement is achieved.
Patent Information
- Application Number
- CN202510081807.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-20
AI Technical Summary
In the edge computing scenario of Internet of Vehicles, there are problems of user and data privacy leakage. Traditional blockchain technology has the limitations of high storage costs, large computing power overhead and low throughput, making it difficult to adapt to the characteristics of edge device resources limited and terminal nodes with high speed movement.
The layered blockchain network model is adopted, including the cloud center, terminal layer and edge layer, and vehicle identity privacy authentication and data privacy protection are carried out through the edge blockchain architecture, and dynamically generated vehicle credentials and attribute encryption technology is used to ensure data confidentiality and fine-grained access control.
It realizes effective user and data privacy protection in the edge computing scenario of Internet of Vehicles, reduces the risks of internal and external attacks, provides a safe and trustworthy network environment, and enhances the security of Internet of Vehicles system.
Smart Images

Figure CN119945657A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a lightweight privacy protection model for edge devices of an Internet of Vehicles (IoV), and in particular to an IoV layered blockchain privacy protection method. Background Art
[0002] The large-scale application of intelligent connected vehicles and the rich business forms provided by the Internet of Vehicles have promoted the continuous development of vehicles towards intelligence and networking. These businesses usually require intensive computing processing, and cloud computing centers can provide high-performance computing services for this purpose. However, long-distance transmission often cannot meet the strict low-latency business requirements in the Internet of Vehicles. Real-time analysis of massive vehicle data in the cloud is also extremely challenging for computing power and network bandwidth.
[0003] Intelligent connected vehicles, roadside units, base stations and other intelligent terminal devices in the Internet of Vehicles have certain computing, storage and communication capabilities, and can act as edge computing servers, exchanging data, executing computing tasks and obtaining processing results, realizing the sinking of computing power on the roadside, reducing the pressure of cloud computing, and thus providing accurate perception of traffic conditions and low-latency decision-making services. However, due to the randomness, decentralization and self-organization of network terminal equipment networking, when devices frequently interact and exchange sensitive information, it is very easy to cause the leakage of personal privacy and sensitive data, exposing the vehicle network to a variety of security and privacy threats, which directly affects the security of the intelligent connected vehicle system.
[0004] There have been some studies at home and abroad on vehicle identity authentication and data privacy protection in the edge computing scenario of the Internet of Vehicles. However, in general, traditional blockchain technology itself has the limitations of high storage cost, large computing power overhead and low throughput. It is difficult to adapt to the characteristics of limited edge device resources, high-speed terminal node movement and dynamic topological structure changes in this scenario. In addition, the existing solutions have insufficient identity privacy protection, difficulty in cross-region authentication, and single authorization power concentration. How to use effective mechanisms to manage and transmit large amounts of data in the mobile edge computing scenario of the Internet of Vehicles to solve the user and data privacy leakage problems has become an urgent problem that needs to be solved. Summary of the invention
[0005] Edge devices in the Internet of Vehicles are difficult to protect due to their dispersed locations and are often connected to critical infrastructure, so they are often the target of attacks, which can easily lead to the leakage of user data privacy. Therefore, it is necessary to study the data security protection model in the edge computing environment. Using the layered blockchain network model, we design a distributed trusted interaction environment for the Internet of Vehicles to ensure the authenticity, integrity and reliability of the on-chain data, while taking into account the limited resources of edge devices.
[0006] To achieve the above invention objectives, this application proposes a lightweight Internet of Vehicles hierarchical blockchain privacy protection method, including the following contents:
[0007] 1) Adopting a hierarchical distributed architecture to build a layered blockchain for the Internet of Vehicles: including a cloud center, a terminal layer, and an edge layer; the cloud center provides high-performance computing service capabilities and network services; the terminal layer is composed of vehicles and corresponding roadside units. Vehicles, as the main nodes of the terminal layer, collect surrounding environment information through on-board sensors and transmit shared information through communication modules. The terminal layer is divided into multiple terminal sub-areas according to the geographical area covered by the vehicle network, and each terminal sub-area constructs a terminal blockchain; the edge layer is jointly constructed by roadside facilities and edge servers, such as roadside units and base stations, to store data snapshots of transactions in each terminal blockchain. The edge blockchain uses a hashgraph structure to establish multiple parallel blockchains. Each chain can store transaction information in the terminal blockchain corresponding to a terminal sub-area and synchronize transaction information in other terminal sub-areas. Different terminal sub-areas use edge blockchains to achieve cross-regional data sharing;
[0008] 2) Vehicle identity privacy authentication under the edge blockchain architecture: Relying on the constructed edge layer blockchain network, it is separated from the centralized authentication mode. The edge blockchain acts as a trusted third party. The identity authentication registration of the terminal layer vehicle node is regarded as a transaction on the edge blockchain network. The vehicle identity privacy protection is verified by dynamically generating vehicle credentials. The verified vehicles are connected to the terminal blockchain governed by the edge facilities, and the registration and verification information is stored on the edge blockchain. The terminal layer vehicle nodes first interact directly with the roadside units covering them and send registration and authentication requests. Then, the roadside units send the authentication requests to the edge blockchain to obtain verification and confirmation from other edge devices. Finally, the vehicle nodes that pass the verification request are authenticated with the help of the cryptographic knowledge of bilinear pairings.
[0009] 3) Data privacy protection under the edge blockchain architecture: Introduce attribute encryption technology to resist the possibility of edge servers leaking sensitive data privacy. Through multiple edge servers jointly generate user attribute keys, all nodes on the edge blockchain, including authorized nodes, cannot obtain the user attribute keys in full to avoid key leakage; the attribute encryption technology, that is, introduces a linear access structure in the ciphertext that grows linearly with the increase of the access structure, and generates a key policy from the access structure. Only when the user's attributes meet the access structure of the ciphertext can the ciphertext be decrypted, thereby realizing the confidentiality of shared data and fine-grained fast access control.
[0010] Furthermore, the above step 2) includes:
[0011] 2.1) Vehicle User U i Select a User IDi , and forward the identifier to the edge facility BS j ;
[0012] 2.2) Edge Facilities BS j Receive user ID i , broadcast it to all other edge facilities on the edge blockchain network for verification; once the majority of nodes pass the verification request submitted by the user, BS j The public parameters of the network will be forwarded to user U i , the common parameters include the following:
[0013] {H1,H2,H3,P,p,e,G1,G2,g,Gen(·),Rep(·),γ}
[0014] Among them, H1, H 2、 H3 is a hash function, P is the generator of the additive cyclic group G1, G2 is the cyclic multiplicative group, p is the prime order of G1, G2 and g = e(P, P) ∈ G2, Gen() and Rep() are the generating function and regenerating function of the fuzzy extractor bio-cryptographic system respectively, and γ is the fault tolerance of the fuzzy extractor;
[0015] 2.3) User U i After receiving the public parameters, choose a∈Z p And calculate its key S i :
[0016] S i =(a+H1(ID i ) -1 )
[0017] Among them, Z p is a set of integers modulo p, and a is a random number.
[0018] Its public key is calculated as: PK i =S i P;
[0019] User Ui calculates the public key PK i Forwarded to edge facility BS j ;
[0020] 2.4) Use lightweight elliptic curve cryptography to dynamically generate public keys and digital signatures for vehicle nodes in edge computing scenarios to enhance vehicle identity privacy;
[0021] 2.5) Edge Facilities BS j User U i Contains public key, identity ID i, digitally signed enhanced identities are registered and broadcast to the edge blockchain for further addition to the tracking of verified users in the distributed ledger; edge facility BS j Forward the identities and public keys of all edge facilities in the network to user U i :[(BS1,PK1),(BS2,PK2),...,(BS j ,PK j )];
[0022] 2.6) User U i After receiving the edge facility’s identity and its respective public key, the fuzzy extractor biometric cryptographic system’s generating function is used to calculate (α i ,β i )←Gen(f i ), and are encrypted and securely saved as the following parameters:
[0023]
[0024] Among them, f i For user U i The biometric information is used as the input of the generating function Gen(.) to obtain a biometric key α i and a public regeneration parameter β i , when an input satisfy When , the fuzzy extractor regenerates the function Rep(.), given by and β i Calculate α i ,Right now In this way, a secure biometric key is extracted from the user's biometric features without directly storing sensitive information; the obtained biometric key is used to generate the hash key H1(α i ) to the identity ID i 、Password PW i and key S i The connection string is encrypted to generate d i ; Otherwise, decrypt d i ID available i , PW i , using it to generate the hash key H2 (ID i ||PW i ) for the collected edge facility identity BS j and public key PK j Encryption Generate D i ; This ensures that even if the mobile terminal is hacked, it cannot access the encrypted information.
[0025] Furthermore, the above step 2.4) specifically includes:
[0026] 2.4.1) Initialization of the public key: The key S i 、Password PW i and biometric features i As input, when the given credentials are correct, verify the validity of the current public key, and generate the element P i Will be used in transactions that have not yet been generated, Initiate(S i ,PW i ,f i )→(P i ,Generate).
[0027] 2.4.2) Public key generation: If the public key expiration period λ has expired, P i If it is in an invalid state, regenerate the public key
[0028]
[0029] 2.4.3) Validation of public keys: Based on the idea of randomly generating public keys, no two consecutive public keys are the same. i and the newly generated public key To perform effective verification, if It is believed that Valid, otherwise return to initialization;
[0030] 2.4.4) Initialization of digital signature: According to the public key random generation algorithm of steps 2.4.1)-2.4.3), the required key pair {S i ,PK i};
[0031] 2.4.5) Generation of digital signature: Based on the given user ID i 、Private key S i , Public Key PK i For each transaction message m initiated by the user, the parameters F and D required for the digital signature are calculated respectively, and the signature Sig is generated on the message m. i =(F,D); The generation process of signature parameters takes into account the index information of the transaction I t ; F and D are calculated as follows:
[0032] I t =H3(m),F=(I t .H4(ID i ).P i )∈G1
[0033] D=(FP i .zS i )∈Z p
[0034] Among them, H(.) is a hash function and z is a random number.
[0035] 2.4.6) Verification of digital signature: If the bilinear pairing function is satisfied, the signature held is confirmed to be valid, and the current authentication transaction index and signature held are received, otherwise the authentication transaction is rejected.
[0036] Furthermore, the specific steps of the above step 3) are as follows:
[0037] 3.1) Selection of multiple authorization centers: The holders of the edge blockchain, i.e., all roadside unit nodes, are regarded as the candidate set of multiple authorization centers. n nodes are selected from the candidate set at random probability to form an authorization agency. The authorization agency is divided into authorization nodes and supervision nodes. The authorization node is responsible for initialization and generating the attribute key SK. The supervision node is responsible for reviewing the work of the authorization node and reviewing the attribute set of the user.
[0038] 3.2) The selected multiple authorized nodes jointly generate attribute keys;
[0039] 3.3) Introduce the linear access structure LSSS in the ciphertext, let ap = (A, ρ, T) represent an access policy, where A is a l×n secret matrix, ρ is a function that maps the attributes in the access policy to the attribute sequence values in the full attribute set, and T = {a ρ(1) ,...,a ρ(l)} is a set of attribute values; randomly select vector Where sv is the secret value to be shared, Denote as the i-th row vector of the access strategy matrix A, calculate As the secret shared value of each attribute ρ(x) in the access policy; if {ω x} x∈A is a set of restitution coefficients, then Σ ρ(x)∈A ω x A x =(1,0,...,0), so that the secret shared value can be recovered.
[0040] Furthermore, the above step 3.2) specifically includes:
[0041] 3.2.1) An authorized node in the multi-authorization center candidate set selects a random number t to regenerate a new key, which is used to ultimately generate the user's attribute key, and uses the user's public key to protect the random number t. The newly generated key and the encrypted random number t are stored in the edge blockchain;
[0042] 3.2.2) Another authorization node in the multi-authorization center candidate set uses the ciphertext generated by the random number t to encrypt and encapsulate the hash value of the user attribute set to prevent the attribute key from being generated using an attribute set that does not match the user;
[0043] 3.2.3) On the user side, the encrypted attribute set is decrypted using the user's private key to determine whether the user and the attribute set match. If the match is successful, the newly generated key is used to generate an attribute key for the user.
[0044] The beneficial effects of the present invention are as follows:
[0045] (1) Based on the layered blockchain network model, the present invention uses a game strategy between the computational complexity of the enhanced security model and the requirement of low latency for vehicles. Starting from the identity authentication that enhances user privacy, the method of dynamically generating public keys is used to eliminate the possibility of internal attackers tracking user public keys on the blockchain edge network. At the same time, in the process of vehicle identity authentication, the hash index information of inter-vehicle transactions is added to restrict vehicle users from tampering with messages, so as to achieve the purpose of resisting various forms of internal attacks on the Internet of Vehicles. Finally, a lightweight Internet of Vehicles privacy protection security solution is generated.
[0046] (2) The present invention adopts an effective mechanism management and transmission to solve the problem of user and data privacy leakage, provides a safe and reliable network environment for parties that do not trust each other, and has achieved good application in protecting vehicle users and data privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a structural schematic diagram of the present invention;
[0048] Figure 2 The hierarchical blockchain network architecture of the present invention;
[0049] Figure 3 It is a multi-authorized node architecture based on attribute encryption. DETAILED DESCRIPTION
[0050] Based on the layered blockchain network model, the present invention uses a strategy of increasing the complexity of the security model and the real-time nature of the calculation to start from the identity authentication that enhances user privacy, and adopts a method of dynamically generating public keys to eliminate the possibility of internal attackers tracking user public keys on the blockchain edge network. At the same time, in the process of vehicle identity authentication, the hash index information of inter-vehicle transactions is added to restrict vehicle users from tampering with messages, so as to achieve the purpose of resisting various forms of internal attacks on the Internet of Vehicles; multiple authorization centers are dynamically generated and attribute keys are jointly generated, and a lightweight access structure with information hiding is used to provide a fine-grained data access control strategy to effectively prevent internal collusion attacks. Finally, a lightweight Internet of Vehicles privacy protection security solution is generated.
[0051] like Figure 1 As shown, the present invention is a lightweight Internet of Vehicles hierarchical blockchain privacy protection method, including the following contents:
[0052] 1) Using a hierarchical distributed architecture to build a layered blockchain for the Internet of Vehicles: Figure 2 As shown, it includes a cloud center, a terminal layer and an edge layer; the cloud center provides high-performance computing service capabilities and network services; the terminal layer is composed of vehicles and corresponding roadside units. Vehicles, as the main nodes of the terminal layer, collect surrounding environment information through on-board sensors and transmit shared information through communication modules. The terminal layer is divided into multiple terminal sub-areas according to the geographical area covered by the vehicle network, and each terminal sub-area constructs a terminal blockchain; the edge layer is jointly constructed by roadside facilities and edge servers, and stores data snapshots of transactions in each terminal blockchain, such as roadside units and base stations. The edge blockchain uses a hashgraph structure to establish multiple parallel blockchains. Each chain can store transaction information in the terminal blockchain corresponding to a terminal sub-area, and can synchronize transaction information in other terminal sub-areas. Different terminal sub-areas use edge blockchains to achieve cross-regional data sharing;
[0053] 2) Vehicle identity privacy authentication under the edge blockchain architecture: Relying on the constructed edge layer blockchain network, it is separated from the centralized authentication mode. The edge blockchain acts as a trusted third party. The identity authentication registration of the terminal layer vehicle node is regarded as a transaction on the edge blockchain network. The vehicle identity privacy protection is verified by dynamically generating vehicle credentials. The verified vehicles are connected to the terminal blockchain governed by the edge facilities, and the registration and verification information is stored on the edge blockchain. The terminal layer vehicle nodes first interact directly with the roadside units covering them and send registration and authentication requests. Then, the roadside units send the authentication requests to the edge blockchain to obtain verification and confirmation from other edge devices. Finally, the vehicle nodes that pass the verification request are authenticated with the help of the cryptographic knowledge of bilinear pairings.
[0054] 3) Data privacy protection under the edge blockchain architecture: Introduce attribute encryption technology to resist the possibility of edge servers leaking sensitive data privacy. Through multiple edge servers jointly generate user attribute keys, all nodes on the edge blockchain, including authorized nodes, cannot obtain the user attribute keys in full to avoid key leakage; the attribute encryption technology, that is, introduces a linear access structure in the ciphertext that grows linearly with the increase of the access structure, and generates a key policy from the access structure. Only when the user's attributes meet the access structure of the ciphertext can the ciphertext be decrypted, thereby realizing the confidentiality of shared data and fine-grained fast access control.
[0055] As a preferred embodiment of the present invention, step 2) includes:
[0056] 2.1) Vehicle User U i Select a User ID i , and forward the identifier to the edge facility BS j ;
[0057] 2.2) Edge Facilities BS j Receive user ID i , broadcast it to all other edge facilities on the edge blockchain network for verification; once the majority of nodes pass the verification request submitted by the user, BS j The public parameters of the network will be forwarded to user U i , the common parameters include the following:
[0058] {H1,H2,H3,P,p,e,G1,G2,g,Gen(·),Rep(·),γ}
[0059] Among them, H1, H 2、 H3 is a hash function, P is the generator of the additive cyclic group G1, G2 is the cyclic multiplicative group, p is the prime order of G1, G2 and g = e(P, P) ∈ G2, Gen() and Rep() are the generating function and regenerating function of the fuzzy extractor bio-cryptographic system respectively, and γ is the fault tolerance of the fuzzy extractor;
[0060] 2.3) User U i After receiving the public parameters, choose a∈Z p And calculate its key S i :
[0061] S i =(a+H1(ID i ) -1 )
[0062] Among them, Z p is a set of integers modulo p, and a is a random number.
[0063] Its public key is calculated as: PK i =S i P;
[0064] User Ui calculates the public key PK i Forwarded to edge facility BS j ;
[0065] 2.4) Use lightweight elliptic curve cryptography to dynamically generate public keys and digital signatures for vehicle nodes in edge computing scenarios to enhance vehicle identity privacy;
[0066] 2.5) Edge Facilities BS j User Ui Contains public key, identity ID i , digitally signed enhanced identities are registered and broadcast to the edge blockchain for further addition to the tracking of verified users in the distributed ledger; edge facility BS j Forward the identities and public keys of all edge facilities in the network to user U i :[(BS1,PK1),(BS2,PK2),...,(BS j ,PK j )];
[0067] 2.6) User U i After receiving the edge facility’s identity and its respective public key, the fuzzy extractor biometric cryptographic system’s generating function is used to calculate (α i ,β i )←Gen(f i ), and are encrypted and securely saved as the following parameters:
[0068]
[0069] Among them, f i For user U i The biometric information is used as the input of the generating function Gen(.) to obtain a biometric key α i and a public regeneration parameter β i , when an input satisfy When , the fuzzy extractor regenerates the function Rep(.), given by and β i Calculate α i ,Right now In this way, a secure biometric key is extracted from the user's biometric features without directly storing sensitive information; the obtained biometric key is used to generate the hash key H1(α i ) to the identity ID i 、Password PW i and key S i The connection string is encrypted to generate d i ; Otherwise, decrypt d i ID available i , PW i , using it to generate the hash key H2 (ID i ||PW i ) for the collected edge facility identity BS j and public key PK j Encryption Generate D i ; This ensures that even if the mobile terminal is hacked, it cannot access the encrypted information.
[0070] As a preferred embodiment of the present invention, step 2.4) specifically includes:
[0071] 2.4.1) Initialization of the public key: The key S i 、Password PW i and biometric features i As input, when the given credentials are correct, verify the validity of the current public key, and generate the element P i Will be used in transactions that have not yet been generated, Initiate(S i ,PW i ,f i )→(P i ,Generate).
[0072] 2.4.2) Public key generation: If the public key expiration period λ has expired, P i If it is in an invalid state, regenerate the public key
[0073] 2.4.3) Validation of public keys: Based on the idea of randomly generating public keys, no two consecutive public keys are the same. i and the newly generated public key To perform effective verification, if It is believed that Valid, otherwise return to initialization;
[0074] 2.4.4) Initialization of digital signature: According to the public key random generation algorithm of steps 2.4.1)-2.4.3), the required key pair {S i ,PK i};
[0075] 2.4.5) Generation of digital signature: Based on the given user ID i 、Private key S i , Public Key PK i For each transaction message m initiated by the user, the parameters F and D required for the digital signature are calculated respectively, and the signature Sig is generated on the message m. i =(F,D); The generation process of signature parameters takes into account the index information of the transaction I t ; F and D are calculated as follows:
[0076] I t =H3(m),F=(I t .H4(ID i ).P i )∈G1
[0077] D=(FP i .zS i )∈Z p
[0078] Among them, H(.) is a hash function and z is a random number.
[0079] 2.4.6) Verification of digital signature: If the bilinear pairing function is satisfied, the signature held is confirmed to be valid, and the current authentication transaction index and signature held are received, otherwise the authentication transaction is rejected.
[0080] As a preferred embodiment of the present invention, Figure 3 As shown, the specific steps of step 3) are as follows:
[0081] 3.1) Selection of multiple authorization centers: The holders of the edge blockchain, i.e., all roadside unit nodes, are regarded as the candidate set of multiple authorization centers. n nodes are selected from the candidate set at random probability to form an authorization agency. The authorization agency is divided into authorization nodes and supervision nodes. The authorization node is responsible for initialization and generating the attribute key SK. The supervision node is responsible for reviewing the work of the authorization node and reviewing the attribute set of the user.
[0082] 3.2) The selected multiple authorized nodes jointly generate attribute keys;
[0083] 3.3) Introduce the linear access structure LSSS in the ciphertext, let ap = (A, ρ, T) represent an access policy, where A is a l×n secret matrix, ρ is a function that maps the attributes in the access policy to the attribute sequence values in the full attribute set, and T = {a ρ(1) ,...,a ρ(l)} is a set of attribute values; randomly select vector Where sv is the secret value to be shared, Denote as the i-th row vector of the access strategy matrix A, calculate As the secret shared value of each attribute ρ(x) in the access policy; if {ω x} x∈A is a set of restitution coefficients, then Σ ρ(x)∈A ω x A x =(1,0,...,0), so that the secret shared value can be recovered.
[0084] As a preferred embodiment of the present invention, step 3.2) specifically includes:
[0085] 3.2.1) An authorized node in the multi-authorization center candidate set selects a random number t to regenerate a new key, which is used to ultimately generate the user's attribute key, and uses the user's public key to protect the random number t. The newly generated key and the encrypted random number t are stored in the edge blockchain;
[0086] 3.2.2) Another authorization node in the multi-authorization center candidate set uses the ciphertext generated by the random number t to encrypt and encapsulate the hash value of the user attribute set to prevent the attribute key from being generated using an attribute set that does not match the user;
[0087] 3.2.3) On the user side, the encrypted attribute set is decrypted using the user's private key to determine whether the user and the attribute set match. If the match is successful, the newly generated key is used to generate an attribute key for the user.
[0088] The present invention uses a lightweight privacy protection authentication scheme to ensure that each vehicle entity that joins the terminal layer blockchain has a correct identity and ensures that only the correct entity can obtain the correct information, effectively resisting attacks from external adversaries. In addition, in order to further prevent internal adversaries with legitimate identities, dynamically generated public keys and digital signatures are used for transactions, and cryptographic primitives based on bilinear pairing are used to propose an enhanced privacy protection scheme to ensure the non-traceability and anonymity of vehicle users (terminal nodes), thereby resisting various forms of internal attacks, and proposing a flexible access control strategy for sensitive data of multiple authorization centers, ultimately improving the security of Internet of Vehicles users' privacy information.
Claims
1. A lightweight Internet of Vehicles hierarchical blockchain privacy protection method, characterized in that: It includes the following: 1) A hierarchical distributed architecture is used to build a layered blockchain for the Internet of Vehicles: including a cloud center, a terminal layer, and an edge layer; the cloud center provides high-performance computing service capabilities and network services; the terminal layer is composed of vehicles and corresponding roadside units. As the main node of the terminal layer, the vehicle collects surrounding environment information through on-board sensors and transmits shared information through communication modules. The terminal layer is divided into multiple terminal sub-areas according to the geographical area covered by the vehicle network, and each terminal sub-area constructs a terminal blockchain; the edge layer is jointly constructed by roadside facilities and edge servers to store data snapshots of transactions in each terminal blockchain. The edge blockchain uses a hashgraph structure to establish multiple parallel blockchains. Each chain can store transaction information in the terminal blockchain corresponding to a terminal sub-area and synchronize transaction information in other terminal sub-areas. Different terminal sub-areas use edge blockchains to achieve cross-regional data sharing; 2) Vehicle identity privacy authentication under the edge blockchain architecture: Relying on the constructed edge layer blockchain network, it is separated from the centralized authentication mode. The edge blockchain acts as a trusted third party. The identity authentication registration of the terminal layer vehicle node is regarded as a transaction on the edge blockchain network. The vehicle identity privacy protection is verified by dynamically generating vehicle credentials. The verified vehicles are connected to the terminal blockchain governed by the edge facilities, and the registration and verification information is stored on the edge blockchain. The terminal layer vehicle nodes first interact directly with the roadside units covering them and send registration and authentication requests. Then, the roadside units send the authentication requests to the edge blockchain to obtain verification and confirmation from other edge devices. Finally, the vehicle nodes that pass the verification request are authenticated with the help of the cryptographic knowledge of bilinear pairings. 3) Data privacy protection under the edge blockchain architecture: Introduce attribute encryption technology to resist the possibility of edge servers leaking sensitive data privacy. Through multiple edge servers jointly generate user attribute keys, all nodes on the edge blockchain, including authorized nodes, cannot obtain the user attribute keys in full to avoid key leakage; the attribute encryption technology, that is, introduces a linear access structure in the ciphertext that grows linearly with the increase of the access structure, and generates a key policy from the access structure. Only when the user's attributes meet the access structure of the ciphertext can the ciphertext be decrypted, thereby realizing the confidentiality of shared data and fine-grained fast access control.
2. According to claim 1, a lightweight vehicle networking layered blockchain privacy protection method is characterized in that: The step 2) comprises: 2.1) Vehicle User U i Select a User ID i , and forward the identifier to the corresponding edge facility BS j ; 2.2) Edge Facilities BS j Receive user ID i , broadcast it to all other edge facilities on the edge blockchain network for verification; once most nodes pass the verification request submitted by the user, BS j The public parameters of the network will be forwarded to user U i , the common parameters include the following: {H1,H2,H3,P,p,e,G1,G2,g,Gen(·),Rep(·),γ} Among them, H1, H 2、 H3 is a hash function, P is the generator of the additive cyclic group G1, G2 is the cyclic multiplicative group, p is the prime order of G1, G2 and g = e(P, P) ∈ G2, Gen() and Rep() are the generating function and regenerating function of the fuzzy extractor bio-cryptographic system respectively, and γ is the fault tolerance of the fuzzy extractor; 2.3) User U i After receiving the public parameters, choose a∈Z p And calculate its key S i : S i =(a+H1(ID i ) -1 )P Among them, Z p is a set of integers modulo p, a is a random number; Its public key is calculated as: PK i =S i P; User Ui calculates the public key PK i Forwarded to edge facility BS j ; 2.4) Use lightweight elliptic curve cryptography to dynamically generate public keys and digital signatures for vehicle nodes in edge computing scenarios to enhance vehicle identity privacy; 2.5) Edge Facilities BS j User U i Contains public key, identity ID i , digitally signed enhanced identities are registered and broadcast to the edge blockchain for further addition to the tracking of verified users in the distributed ledger; edge facility BS j Forward the identities and public keys of all edge facilities in the network to user U i :[(BS1,PK1),(BS2,PK2),...,(BS j ,PK j )]; 2.6) User U i After receiving the edge facility’s identity and its respective public key, the fuzzy extractor biometric cryptographic system’s generating function is used to calculate (α i ,β i )←Gen(f i ), and are encrypted and securely saved as the following parameters: Among them, f i For user U i The biometric information is used as the input of the generating function Gen(.) to obtain a biometric key α i and a public regeneration parameter β i , when an input f i * Satisfy |f i * -f i |<γ, the fuzzy extractor regenerates the function Rep(.), which is given by f i * and β i Calculate α i , that is, α i ←Rep(f i * ,β i ); In this way, a secure biometric key is extracted from the user's biometric features without directly storing sensitive information; the obtained biometric key is used to generate the hash key H1 (α i ) to the identity ID i 、Password PW i and key S i The connection string is encrypted to generate d i ; Otherwise, decrypt d i ID available i , PW i , using it to generate the hash key H2 (ID i ||PW i ) for the collected edge facility identity BS j and public key PK j Encryption Generate D i ; This ensures that even if the mobile terminal is hacked, it cannot access the encrypted information.
3. A lightweight vehicle networking layered blockchain privacy protection method according to claim 2, characterized in that: The step 2.4) comprises: 2.4.1) Initialization of the public key: The key S i 、Password PW i and biometric features i As input, when the given credentials are correct, verify the validity of the current public key, and generate the element P i Will be used in transactions that have not yet been generated, Initiate(S i ,PW i ,f i )→(P i ,Generate); 2.4.2) Public key generation: If the public key expiration period λ has expired, P i If it is in an invalid state, regenerate the public key 2.4.3) Validation of public keys: Based on the idea of randomly generating public keys, no two consecutive public keys are the same. i and the newly generated public key To perform effective verification, if It is believed that Valid, otherwise return to initialization; 2.4.4) Initialization of digital signature: According to the public key random generation algorithm of steps 2.4.1)-2.4.3), the required key pair {S i ,PK i }; 2.4.5) Generation of digital signature: Based on the given user ID i 、Private key S i , Public Key PK i For each transaction message m initiated by the user, the parameters F and D required for the digital signature are calculated respectively, and the signature Sig is generated on the message m. i =(F,D); The generation process of signature parameters takes into account the index information of the transaction I t ; F and D are calculated as follows: I t =H3(m),F=(I t .H4(ID i ).P i )∈G1 D=(F.P i .z.S i )∈Z p Among them, H(.) is a hash function, and z is a random number; 2.4.6) Verification of digital signature: If the bilinear pairing function is satisfied, the signature held is confirmed to be valid, and the current authentication transaction index and signature held are received, otherwise the authentication transaction is rejected.
4. According to claim 1, a lightweight vehicle networking layered blockchain privacy protection method is characterized in that: The step 3) comprises: 3.1) Selection of multiple authorization centers: The holders of the edge blockchain, i.e., all roadside unit nodes, are regarded as the candidate set of multiple authorization centers. n nodes are selected from the candidate set at random probability to form an authorization agency. The authorization agency is divided into authorization nodes and supervision nodes. The authorization node is responsible for initialization and generating the attribute key SK. The supervision node is responsible for reviewing the work of the authorization node and reviewing the attribute set of the user. 3.2) The selected multiple authorized nodes jointly generate attribute keys; 3.3) Introduce the linear access structure LSSS in the ciphertext, let ap = (A, ρ, T) represent an access policy, where A is a l×n secret matrix, ρ is a function that maps the attributes in the access policy to the attribute sequence values in the full attribute set, and T = {a ρ(1) ,...,a ρ(l) } is a set of attribute values; randomly select vector Where sv is the secret value to be shared, Denote as the i-th row vector of the access strategy matrix A, calculate As the secret shared value of each attribute ρ(x) in the access policy; if {ω x } x∈A is a set of restitution coefficients, then Σ ρ(x)∈A ω x A x =(1,0,...,0), so that the secret shared value can be recovered.
5. A lightweight vehicle networking layered blockchain privacy protection method according to claim 4, characterized in that: The step 3.2) specifically includes: 3.2.1) An authorized node in the multi-authorization center candidate set selects a random number t to regenerate a new key, which is used to ultimately generate the user's attribute key, and uses the user's public key to protect the random number t. The newly generated key and the encrypted random number t are stored in the edge blockchain; 3.2.2) Another authorization node in the multi-authorization center candidate set uses the ciphertext generated by the random number t to encrypt and encapsulate the hash value of the user attribute set to prevent the attribute key from being generated using an attribute set that does not match the user; 3.2.3) On the user side, the encrypted attribute set is decrypted using the user's private key to determine whether the user and the attribute set match. If the match is successful, the newly generated key is used to generate an attribute key for the user.
Citation Information
Patent Citations
Internet of Vehicles privacy protection trust model based on block chain
CN110300107A
Internet of Vehicles distributed trust system based on HashGraph and trust value calculation method
CN111988381A
Federated learning privacy protection method based on homomorphic encryption in Internet of Vehicles
CN112583575A
LBS privacy protection method in car networking sparse user environment
CN115529150A
Vehicle identity privacy protection method based on block chain in Internet of Vehicles
CN116527342A
Cited By
Internet of vehicles data sharing method, vehicle and system
CN121151872A