A lightweight internet of vehicles hierarchical block chain privacy protection method

By using a layered blockchain network and attribute encryption technology, the problem of user data privacy leakage in edge computing scenarios in the Internet of Vehicles is solved, achieving lightweight identity authentication and data protection, providing a secure and reliable Internet of Vehicles environment, resisting internal attacks, and meeting low latency requirements.

CN119945657BActive Publication Date: 2025-11-28JIANGSU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510081807.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-11-28
Estimated Expiration
2045-01-20

AI Technical Summary

Technical Problem

In edge computing scenarios within the Internet of Vehicles (IoV), traditional blockchain technology suffers from high storage costs, high computing power overhead, low throughput, and insufficient protection of identity privacy. It is also difficult to adapt to the characteristics of limited device resources and dynamic changes in topology, leading to user data privacy leaks.

Method used

A layered blockchain network model is adopted, including a cloud center, a terminal layer, and an edge layer. The edge layer establishes parallel blockchains through a hashgraph structure, combines attribute encryption technology and dynamically generated vehicle credentials for identity authentication and data protection, utilizes a lightweight elliptic curve cryptography system to enhance vehicle identity privacy, and introduces multiple authorization centers for fine-grained access control of sensitive data.

Benefits of technology

It effectively protects user and data privacy in the Internet of Vehicles, provides a secure and reliable network environment, resists internal attacks, ensures the security and anonymity of vehicle-to-vehicle transactions, reduces computational complexity, and meets low latency requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945657B_ABST
    Figure CN119945657B_ABST
Patent Text Reader

Abstract

The present application relates to a lightweight privacy protection model of Internet of Vehicles edge device, in particular to a layered blockchain privacy protection method of Internet of Vehicles.The present application uses the strategy of gambling between the calculation complexity of enhanced security model and the requirement of low delay of vehicle on the basis of layered blockchain network model, starts with the authentication of enhanced user privacy, adopts the method of dynamically generating public key to eliminate the possibility of internal attacker tracking the public key of user on the blockchain edge network, increases the hash index information of transaction between vehicles in the process of vehicle authentication, limits the tampering of vehicle user to message, and achieves the purpose of resisting various forms of internal attack of Internet of Vehicles. Effective mechanism management and transmission are adopted to solve the problem of user and data privacy leakage, provide a safe and reliable network environment for mutually distrustful parties, and achieve good application in protecting vehicle user and data privacy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a lightweight privacy protection model for edge devices in the Internet of Vehicles, and in particular to a layered blockchain privacy protection method for the Internet of Vehicles. BACKGROUND

[0002] The large-scale application of intelligent and networked vehicles and the rich business forms provided by the Internet of Vehicles have promoted the continuous development of vehicles towards intelligence and networking. These businesses often require intensive computing processing, and cloud computing centers can provide high-performance computing service capabilities. However, long-distance transmission often cannot meet the strict low-latency business requirements in the Internet of Vehicles, and real-time analysis of massive vehicle data in the cloud is also extremely challenging in terms of computing power and network bandwidth.

[0003] Intelligent terminal devices such as intelligent and networked vehicles, roadside units, and base stations in the Internet of Vehicles have certain computing, storage, and communication capabilities, and can act as edge computing servers. They interact with each other to transmit data, perform computing tasks, and obtain processing results, thus realizing the sinking of computing power at the roadside and reducing the pressure on cloud computing, thereby providing accurate perception of traffic conditions and low-latency decision-making services. However, due to the randomness, dispersion, and self-organization of network terminal device networking, when devices frequently interact and exchange sensitive information, it is easy to lead to the leakage of personal privacy and sensitive data, making the vehicle network face various security and privacy threats, thereby directly affecting the safety of the intelligent and networked vehicle system.

[0004] There have been some research on vehicle identity authentication and data privacy protection in the edge computing scenario of the Internet of Vehicles, but overall, traditional blockchain technology has limitations such as high storage cost, large computing power consumption, and low throughput, making it difficult to adapt to the characteristics of limited resources of edge devices, high-speed movement of terminal nodes, and dynamic changes in topology in this scenario. Moreover, existing solutions lack identity privacy protection, are difficult to cross-zone authentication, and have centralized single authorization power. Therefore, how to effectively manage and transmit a large amount of data in the mobile edge computing scenario of the Internet of Vehicles using an effective mechanism to solve the problem of user and data privacy leakage has become an urgent problem to be solved. SUMMARY

[0005] Edge devices in the Internet of Vehicles are difficult to protect due to their dispersed locations and are often connected to critical infrastructure, making them a target for attacks and causing the leakage of user data privacy. Therefore, it is necessary to study a data security protection model in the edge computing environment. Using a layered blockchain network model, we design a distributed trusted interaction environment for the Internet of Vehicles to ensure the authenticity, integrity, and reliability of data on the chain, while considering the limited resources of edge devices.

[0006] To achieve the above object, the application provides a lightweight Internet of Vehicles hierarchical blockchain privacy protection method, which comprises the following contents.

[0007] 1) A hierarchical distributed architecture is adopted to construct the hierarchical blockchain of Internet of Vehicles, which comprises a cloud center, a terminal layer and an edge layer; the cloud center provides high-performance computing service capability and network service; the terminal layer is composed of vehicles and corresponding roadside units, the vehicles as the main nodes of the terminal layer collect surrounding environment information through vehicle-mounted sensors and transmit shared information through a communication module, the terminal layer is divided into a plurality of terminal sub-regions according to the geographical area covered by the vehicle network, and each terminal sub-region constructs a terminal blockchain; the edge layer is jointly constructed by roadside facilities and edge servers, such as roadside units and base stations, and stores data snapshots of transactions in each terminal blockchain, and the edge blockchain uses a hashgraph structure to establish a plurality of parallel blockchains, each chain can store transaction information in the terminal blockchain corresponding to each terminal sub-region and synchronize transaction information of other terminal sub-regions, and data sharing across regions is realized by means of the edge blockchain between different terminal sub-regions;

[0008] 2) Vehicle identity privacy authentication under the edge blockchain architecture: relying on the constructed edge layer blockchain network, the central authentication mode is abandoned, the edge blockchain acts as a trusted third-party role, the identity authentication registration of the vehicle node of the terminal layer is regarded as a transaction on the edge blockchain network, a dynamic vehicle credential generation method is adopted to verify the identity privacy protection of the vehicle, the vehicle passing the verification is connected to the terminal blockchain governed by the edge facility, and the registration verification information is stored on the edge blockchain; the vehicle node of the terminal layer first directly interacts with the roadside unit covering them, sends a registration and authentication request, then the roadside unit sends the authentication request to the edge blockchain to obtain the verification and confirmation of other edge devices, and finally, the identity of the vehicle node passing the verification request is authenticated by means of the bilinear pair cryptography;

[0009] 3) Data privacy protection under the edge blockchain architecture: the attribute encryption technology is introduced to resist the possibility of sensitive data privacy leakage of the edge server, a user attribute key is jointly generated by multiple edge servers, and all nodes on the edge blockchain, including authorized nodes, cannot obtain the user attribute key in full to avoid leakage of the key; the attribute encryption technology, i.e. introducing a linear access structure that increases linearly with the increase of access structure in the ciphertext, generates a key policy from the access structure, only the attributes of the user meet the access structure of the ciphertext, the ciphertext can be decrypted, realizing the confidentiality and fine-grained fast access control of shared data.

[0010] Further, the above step 2) comprises:

[0011] 2.1) A vehicle user U i select a user identifier IDi And forward the identifier to the relevant edge facility BS. j ;

[0012] 2.2) Peripheral facilities BS j Received user ID i This is broadcast to all other edge facilities on the edge blockchain network for verification; once a majority of nodes approve the user's verification request, BS... j It will then forward the network's public parameters to user U. i The common parameters include the following:

[0013] {H1,H2,H3,P,p,e,G1,G2,g,Gen(·),Rep(·),γ}

[0014] Among them, H1, H 2、 H3 is the hash function, P is the generator of the additive cyclic group G1, G2 is the cyclic multiplicative group, p is the prime order of G1, G2 and g = e(P,P)∈G2, Gen() and Rep() are the generator and regenerator functions of the fuzzy extractor bio-cryptographic system, respectively, and γ is the fault tolerance rate of the fuzzy extractor.

[0015] 2.3) User U i After receiving the common parameters, select a∈Z p And calculate its key S i :

[0016] S i =(a+H1(ID) i ) -1 )P

[0017] Among them, Z p It is the set of integers modulo p, where a is a random number.

[0018] Its public key is calculated as: PK i =S i P;

[0019] User Ui will calculate the public key PK i Forwarded to edge facility BS j ;

[0020] 2.4) Lightweight elliptic curve cryptography is used to dynamically generate public keys and digital signatures for vehicle nodes in edge computing scenarios to enhance vehicle identity privacy.

[0021] 2.5) Peripheral facilities BS j User U i It contains public key, identity ID iDigital signatures enhance identity by registering and broadcasting it to the edge blockchain, enabling further addition to the traceability of verified users in the distributed ledger; edge infrastructure (BS) j Forward the identities and public keys of all edge facilities within the network to user U i :[(BS1,PK1),(BS2,PK2),...,(BS j PK j )];

[0022] 2.6) User U i After receiving the identity of the edge facility and its respective public key, the generator function of the biometric cryptosystem, fuzzy extractor, is used to calculate (α). i ,β i )←Gen(f i ), and encrypt and securely save it as the following parameters:

[0023]

[0024] Among them, f i For user U i The biometric information is used as input to the generator function Gen(.) to obtain a biometric key α. i And a publicly disclosed regeneration parameter β i When a certain input satisfy At that time, the fuzz extractor regeneration function Rep(.) is... and β i Calculate α i ,Right now This method extracts a secure biometric key from the user's biometrics without directly storing sensitive information; the obtained biometric key is then used to generate a hash key H1(α). i To match identity ID i Password PW i and key S i encrypting the connection string to generate d i Conversely, decrypt d i ID can be obtained i PW i Use it to generate the hash key H2(ID) i ||PW i ) BS of collected edge facility identities j PK with public key j Encryption generation D i This ensures that even if a mobile terminal is compromised, it cannot access encrypted information.

[0025] Furthermore, step 2.4) above specifically includes:

[0026] 2.4.1) Initialization of public key: take the secret key S i , the password PW i and the biometric feature f i as input, and generate the element P i to be used in the transaction that has not been generated yet, Initiate(S i , PW i , f i )→(P i , Generate).

[0027] 2.4.2) Generation of public key: if the public key P i is invalid because the expiration time λ has expired, then generate a new public key P

[0028] 2.4.3) Validity verification of public key: according to the idea of randomly generating public keys, no two consecutive public keys are the same. Verify the validity of the expired public key P i and the newly generated public key P . If P i = P , then the public key is valid, otherwise return to initialization.

[0029] 2.4.4) Initialization of digital signature: according to the public key random generation algorithm in steps 2.4.1)-2.4.3), obtain the required key pair {S i , P i};

[0030] 2.4.5) Generation of digital signature: according to the given user identity ID i , the private key S i , the public key P i and the user initiated transaction message m, calculate the required parameters F and D for digital signature respectively, and generate the signature Sig i = (F, D) on the message m. The generation process of the signature parameters takes into account the index information I t of the transaction; the calculation of F and D is as follows:

[0031] I t = H3(m), F = (I t .H4(ID i ).P i ) ∈ G1

[0032] D = (F.P i .z.S i ) ∈ Z p

[0033] where H(.) is a hash function and z is a random number.

[0034] 2.4.6) Verification of digital signature: if the bilinear pairing function is satisfied, it is proved that the held signature is valid, the current held authentication transaction index and signature are received, otherwise the authentication transaction is rejected.

[0035] Further, the above step 3) is specifically as follows:

[0036] 3.1) Selection of multi-authorization center: the holders of the edge blockchain, i.e. all roadside unit nodes, are regarded as a candidate set of multi-authorization center, n nodes are selected from the candidate set at each time according to random probability to form an authorization agency, the authorization agency is divided into an authorized node and a supervision node, the authorized node is responsible for initialization, generating an attribute key SK, and the supervision node is responsible for reviewing the work of the authorized node and reviewing the attribute set of the user;

[0037] 3.2) Joint generation of attribute key by selected multiple authorized nodes;

[0038] 3.3) Linear access structure LSSS is introduced in the ciphertext, and ap=(A, ρ, T) represents an access strategy, where A is an l×n secret matrix, ρ is a function of mapping the attributes in the access strategy to the attribute sequence value in the attribute set, and T={a ρ(1) ,...,a ρ(l)} is the set of attribute values; a random vector is selected, where sv is the secret value to be shared, denoted as the i-th row vector of the access strategy matrix A, and the calculation is as the secret sharing value of each attribute ρ(x) in the access strategy; if {ω x} x∈A is a set of recovery coefficients, then Σ ρ(x)∈A ω x A x =(1, 0,..., 0), so that the secret sharing value can be recovered.

[0039] Further, the above step 3.2) specifically includes:

[0040] 3.2.1) A random number t is selected by an authorized node in the candidate set of the multi-authorization center to regenerate a new key, which is used for finally generating the attribute key of the user, and the random number t is protected by using the public key of the user, the newly generated key and the encrypted random number t are stored in the edge blockchain;

[0041] 3.2.2) Another authorized node in the candidate set of the multi-authorization center uses the ciphertext generated by the random number t to encrypt and encapsulate the hash value of the attribute set of the user, so as to prevent the generation of the attribute key using the attribute set that does not match the user.

[0042] 3.2.3) In the user end, the encrypted attribute set is decrypted by using the user private key, so as to judge whether the user matches the attribute set, and if the matching is successful, the attribute key is generated for the user by using the newly generated key.

[0043] The beneficial effects of the present application are as follows:

[0044] (1) The present application uses the strategy of gambling between the complexity of the enhanced security model and the real-time calculation of the vehicle, starts from enhancing the identity authentication of user privacy, adopts the method of dynamically generating public key to eliminate the possibility of internal attackers tracking the user public key on the edge network of the blockchain, and increases the hash index information of the transaction between vehicles in the process of vehicle identity authentication, limits the tampering of vehicle users to the message, so as to resist various forms of internal attacks of Internet of Vehicles. Finally, a lightweight privacy protection security scheme of Internet of Vehicles is generated.

[0045] (2) The present application adopts effective mechanism management and transmission to solve the problem of user and data privacy leakage, provides a safe and reliable network environment for mutually distrustful parties, and achieves good application in protecting the privacy of vehicle users and data. BRIEF DESCRIPTION OF DRAWINGS

[0046] Figure 1 It is a structural schematic diagram of the present application;

[0047] Figure 2 It is a hierarchical blockchain network architecture of the present application;

[0048] Figure 3 It is a multi-authorization node architecture based on attribute encryption. DETAILED DESCRIPTION

[0049] The present application uses the strategy of gambling between the complexity of the enhanced security model and the real-time calculation of the vehicle, starts from enhancing the identity authentication of user privacy, adopts the method of dynamically generating public key to eliminate the possibility of internal attackers tracking the user public key on the edge network of the blockchain, and increases the hash index information of the transaction between vehicles in the process of vehicle identity authentication, limits the tampering of vehicle users to the message, so as to resist various forms of internal attacks of Internet of Vehicles. Dynamic generation of multiple authorization centers and joint generation of attribute keys, combined with the lightweight access structure of information hiding, provide fine-grained data access control strategy, effectively prevent internal collusion attacks. Finally, a lightweight privacy protection security scheme of Internet of Vehicles is generated.

[0050] As shown in Figure 1 the present application is a lightweight hierarchical blockchain privacy protection method for Internet of Vehicles, which includes the following contents:

[0051] 1) Construct a layered blockchain for the Internet of Vehicles using a hierarchical distributed architecture: such as Figure 2 As shown, the system comprises a cloud center, a terminal layer, and an edge layer. The cloud center provides high-performance computing and network services. The terminal layer consists of vehicles and corresponding roadside units. Vehicles, as the main nodes of the terminal layer, collect environmental information through onboard sensors and transmit shared information via communication modules. The terminal layer is divided into multiple terminal sub-regions based on the geographical area covered by the vehicle network, and each sub-region constructs its own terminal blockchain. The edge layer is jointly constructed by roadside facilities and edge servers, storing snapshots of transaction data in each terminal blockchain. Roadside facilities include roadside units and base stations. The edge blockchain uses a hashgraph structure to establish multiple parallel blockchains. Each chain can store transaction information from the terminal blockchain corresponding to one terminal sub-region and synchronize transaction information from other terminal sub-regions. Different terminal sub-regions achieve cross-regional data sharing through the edge blockchain.

[0052] 2) Vehicle Identity Privacy Authentication under Edge Blockchain Architecture: Relying on the constructed edge layer blockchain network, it departs from the centralized authentication model. The edge blockchain acts as a trusted third party. The identity authentication and registration of terminal layer vehicle nodes are regarded as a transaction on the edge blockchain network. The vehicle identity privacy protection verification is performed by dynamically generating vehicle credentials. The verified vehicle accesses the terminal blockchain managed by the edge facility, and the registration and verification information is stored on the edge blockchain. The terminal layer vehicle nodes first interact directly with the roadside units covering them, sending registration and authentication requests. Then, the roadside units send the authentication requests to the edge blockchain to obtain verification and confirmation from other edge devices. Finally, the identity of the vehicle node that passes the verification request is authenticated by using bilinear pairing cryptography.

[0053] 3) Data privacy protection under edge blockchain architecture: Attribute encryption technology is introduced to resist the possibility of edge servers leaking sensitive data privacy. User attribute keys are generated jointly by multiple edge servers. All nodes on the edge blockchain, including authorized nodes, cannot fully obtain the user attribute keys to avoid key leakage. The attribute encryption technology introduces a linear access structure into the ciphertext, which grows linearly with the increase of the access structure. The key policy is generated from the access structure. Only when the user's attributes match the access structure of the ciphertext can the ciphertext be decrypted, realizing the confidentiality of shared data and fine-grained fast access control.

[0054] As a preferred embodiment of the present invention, step 2) includes:

[0055] 2.1) Vehicle User U i Select a user ID iAnd forward the identifier to the relevant edge facility BS. j ;

[0056] 2.2) Peripheral facilities BS j Received user ID i This is broadcast to all other edge facilities on the edge blockchain network for verification; once a majority of nodes approve the user's verification request, BS... j It will then forward the network's public parameters to user U. i The common parameters include the following:

[0057] {H1,H2,H3,P,p,e,G1,G2,g,Gen(·),Rep(·),γ}

[0058] Among them, H1, H 2、 H3 is the hash function, P is the generator of the additive cyclic group G1, G2 is the cyclic multiplicative group, p is the prime order of G1, G2 and g = e(P,P)∈G2, Gen() and Rep() are the generator and regenerator functions of the fuzzy extractor bio-cryptographic system, respectively, and γ is the fault tolerance rate of the fuzzy extractor.

[0059] 2.3) User U i After receiving the common parameters, select a∈Z p And calculate its key S i :

[0060] S i =(a+H1(ID) i ) -1 )P

[0061] Among them, Z p It is the set of integers modulo p, where a is a random number.

[0062] Its public key is calculated as: PK i =S i P;

[0063] User Ui will calculate the public key PK i Forwarded to edge facility BS j ;

[0064] 2.4) Lightweight elliptic curve cryptography is used to dynamically generate public keys and digital signatures for vehicle nodes in edge computing scenarios to enhance vehicle identity privacy.

[0065] 2.5) Peripheral facilities BS j User U i It contains public key, identity ID iDigital signatures enhance identity by registering and broadcasting it to the edge blockchain, enabling further addition to the traceability of verified users in the distributed ledger; edge infrastructure (BS) j Forward the identities and public keys of all edge facilities within the network to user U i :[(BS1,PK1),(BS2,PK2),...,(BS j PK j )];

[0066] 2.6) User U i After receiving the identity of the edge facility and its respective public key, the generator function of the biometric cryptosystem, fuzzy extractor, is used to calculate (α). i ,β i )←Gen(f i ), and encrypt and securely save it as the following parameters:

[0067]

[0068] Among them, f i For user U i The biometric information is used as input to the generator function Gen(.) to obtain a biometric key α. i And a publicly disclosed regeneration parameter β i When a certain input satisfy At that time, the fuzz extractor regeneration function Rep(.) is... and β i Calculate α i ,Right now This method extracts a secure biometric key from the user's biometrics without directly storing sensitive information; the obtained biometric key is then used to generate a hash key H1(α). i To match identity ID i Password PW i and key S i encrypting the connection string to generate d i Conversely, decrypt d i ID can be obtained i PW i Use it to generate the hash key H2(ID) i ||PW i ) BS of collected edge facility identities j PK with public key j Encryption generation D i This ensures that even if a mobile terminal is compromised, it cannot access encrypted information.

[0069] In a preferred embodiment of the present invention, step 2.4) specifically includes:

[0070] 2.4.1) Initialization of public key: take the secret key S i , the password PW i and the biometric feature f i as input, when the given credentials are correct, verify the validity of the current public key P i which will be used in the transaction that has not been generated, Initiate(S i , PW i , f i )→(P i , Generate).

[0071] 2.4.2) Generation of public key: if the public key P i has expired for the deadline λ, it is in invalid state, then re-generate the public key P

[0072] 2.4.3) Validity verification of public key: according to the idea of randomly generating public key, no two consecutive public keys are the same, perform validity verification on the expired public key P i and the newly generated public key P , if then consider P valid, otherwise return to initialization;

[0073] 2.4.4) Initialization of digital signature: according to the public key random generation algorithm of steps 2.4.1)-2.4.3), get the required key pair {S i , P i};

[0074] 2.4.5) Generation of digital signature: according to the given user identity ID i , the private key S i , the public key P i and the user initiated each transaction message m, calculate the required parameters F and D of digital signature respectively, and generate the signature Sig i =(F, D) on the message m; the generation process of signature parameters considers the index information I t of the transaction; the calculation of F and D is as follows:

[0075] I t =H3(m), F=(I t .H4(ID i ).P i )∈G1

[0076] D=(F.P i .z.S i )∈Z p

[0077] where H() is a hash function, and z is a random number.

[0078] 2.4.6) Verification of digital signature: if the bilinear pairing function is satisfied, it is proved that the held signature is valid, the current held authentication transaction index and signature are received, otherwise the authentication transaction is rejected.

[0079] As a preferred embodiment of the present application, as shown in Figure 3 Step 3) is specifically as follows:

[0080] 3.1) Selection of multi-authorization center: the holders of the edge block chain, i.e. all roadside unit nodes, are regarded as a candidate set of multi-authorization center, n nodes are selected from the candidate set to form an authorization agency according to random probability each time, the authorization agency is divided into an authorized node and a supervision node, the authorized node is responsible for initialization, generating an attribute key SK, and the supervision node is responsible for reviewing the work of the authorized node and reviewing the attribute set of the user;

[0081] 3.2) Joint generation of attribute key by the selected multiple authorized nodes;

[0082] 3.3) Linear access structure LSSS is introduced in the ciphertext, and ap=(A, ρ, T) represents an access strategy, wherein A is an l x n secret matrix, ρ is a function of mapping the attribute in the access strategy to the attribute sequence value in the attribute set, and T={a ρ(1) ,...,a ρ(l)} is the set of attribute values; a random vector is selected, wherein sv is a secret value to be shared, denoted as the i-th row vector of the access strategy matrix A, and the calculation is the secret sharing value of each attribute ρ(x) in the access strategy; if {ω x} x∈A is a set of recovery coefficients, then Σ ρ(x)∈A ω x A x =(1, 0,..., 0), so that the secret sharing value can be recovered.

[0083] As a preferred embodiment of the present application, step 3.2) specifically comprises:

[0084] 3.2.1) A random number t is selected by an authorized node in the candidate set of the multi-authorization center to regenerate a new key, which is used for finally generating the attribute key of the user, and the random number t is protected by using the public key of the user, the newly generated key and the encrypted random number t are stored in the edge block chain;

[0085] 3.2.2) The ciphertext generated by another authorization node in the multi-authorization center candidate set using the random number t is used to encrypt the hash value of the user attribute set to prevent the generation of attribute keys using attribute sets that do not match the user;

[0086] 3.2.3) At the user end, the encrypted attribute set is decrypted using the user private key, thereby determining whether the user and the attribute set match, and if the match is successful, generating an attribute key for the user using the newly generated key.

[0087] The present application uses a lightweight privacy protection authentication scheme to ensure that each vehicle entity joining the terminal layer blockchain has a correct identity, and only the correct entity can obtain the correct information, effectively resisting attacks from external enemies. In addition, in order to further prevent internal enemies with legal identities, a dynamic public key and digital signature are used for transactions, a cryptographic primitive based on bilinear pairing cryptography is used, an enhanced privacy protection scheme is proposed to ensure the untraceability and anonymity of vehicle users (terminal nodes), thereby resisting various forms of internal attacks, a multi-authorization center sensitive data flexible access control strategy is proposed, and finally the security of the privacy information of the Internet of Vehicles users is improved.

Claims

1. A lightweight privacy protection method for a hierarchical blockchain in a vehicle-to-everything network, characterized in that, The application comprises the following contents: 1) A hierarchical distributed architecture is adopted to build a hierarchical blockchain for Internet of Vehicles, including a cloud center, a terminal layer and an edge layer; the cloud center provides high-performance computing service capability and network service; the terminal layer is composed of vehicles and corresponding roadside units, the vehicles as the main nodes of the terminal layer collect surrounding environment information through vehicle-mounted sensors and transmit shared information through a communication module, the terminal layer is divided into multiple terminal sub-regions according to the geographical area covered by the vehicle network, and each terminal sub-region constructs a terminal blockchain; the edge layer is jointly constructed by roadside facilities and edge servers, and stores data snapshots of transactions in each terminal blockchain; the edge blockchain uses a hashgraph structure to establish multiple parallel blockchains, each chain can store transaction information in the terminal blockchain corresponding to a terminal sub-region, and can also synchronize transaction information of other terminal sub-regions; the edge blockchain is used to realize data sharing across regions between different terminal sub-regions; 2) Vehicle identity privacy authentication under the edge blockchain architecture: relying on the constructed edge layer blockchain network, the central authentication mode is abandoned, the edge blockchain acts as a trusted third-party role, the identity authentication registration of the vehicle node in the terminal layer is regarded as a transaction on the edge blockchain network, a dynamic vehicle credential generation method is adopted to verify the identity privacy protection of the vehicle, the vehicle passing the verification is connected to the terminal blockchain governed by the edge facility, and the registration verification information is stored on the edge blockchain; the vehicle node in the terminal layer first directly interacts with the roadside unit covering it, sends a registration and authentication request, then the roadside unit sends the authentication request to the edge blockchain to obtain the verification and confirmation of other edge devices, finally, the identity of the vehicle node passing the verification request is authenticated by means of the bilinear pair cryptography; 3) Data privacy protection under the edge blockchain architecture: the attribute encryption technology is introduced to resist the possibility of sensitive data privacy leakage of the edge server, the user attribute key is jointly generated by multiple edge servers, and the user attribute key cannot be completely obtained by all nodes on the edge blockchain including the authorized nodes, so as to avoid leakage of the key; the attribute encryption technology, i.e. introducing a linear access structure that increases linearly with the increase of access structure in the ciphertext, generates a key policy from the access structure, only the attributes of the user meet the access structure of the ciphertext, the ciphertext can be decrypted, the confidentiality and fine-grained fast access control of shared data are realized. 2.The lightweight hierarchical blockchain privacy protection method for Internet of Vehicles according to claim 1, characterized in that, The step 2) comprises: 2.1) Vehicle user U i Selecting a user identity ID i and forwarding the identity to the belonging edge facility BS j ; 2.2) Edge Facility BS j Upon receiving the user identification ID i , it broadcasts it to all other edge facilities on the edge blockchain network for validation; once the majority of nodes pass the validation request submitted by the user, the BS j forwards the public parameters of the network to the user U i , which include the following: {H1, H2, H3, P, p, e, G1, G2, g, Gen(·), Rep(·), γ} wherein H1, H 2、 H3 is a hash function, P is a generator of the additive cyclic group G1, G2 is a cyclic multiplicative group, p is a prime order of G1, G2 and g = e(P, P) e G2, Gen() and Rep() are a generation function and a regeneration function of the fuzzy extractor biometric password system respectively, and γ is a fault tolerance rate of the fuzzy extractor. 2.3) User U i Upon reception of the public parameters, select a e Z p and compute its key S i : S i = (a + H1(ID i ) -1 )P wherein Z p is a set of integers modulo p, and a is a random number; The public key thereof is calculated as: PK i = S i P; The user Ui forwards the computed public key PK i to the edge facility BS j ; 2.4) A lightweight elliptic curve cryptography system is used to dynamically generate the public key and digital signature of the vehicle node in the edge computing scenario, so as to enhance the vehicle identity privacy; 2.5) Edge facilities BS j The user U i registers and broadcasts to the edge blockchain his enhanced identity containing the public key, the identity ID i , the digital signature, in order to be further added to the tracking of the verified users in the distributed ledger; the edge facility BS j forwards to the user U i the identities and public keys of all the edge facilities within the network: [(BS1, PK1), (BS2, PK2),..., (BS j , PK j )]. 2.6) User U i Upon receiving the identity of the edge facility and its respective public key, the generation function of the fuzzy extractor biometric system is used to compute (a i , b i ) <- Gen(f i ) and encrypt and securely store as the following parameters: where f i is the biometric information of the user U i , which is used as the input of the generating function Gen(.) to obtain a biometric key α i and a public regeneration parameter β i . When a certain input f i * satisfies |f i * -f i | < γ, the fuzzy extractor regeneration function Rep(.) is calculated from f i * and β i to obtain α i , i.e. α i ← Rep(f i * , β i ); thus the secure biometric key is extracted from the biometric information of the user without directly storing sensitive information; the obtained biometric key is used to continue generating the hash key H1(α i ) to encrypt the connection string of the identity ID i , the password PW i and the key S i to generate d i ; conversely, the decryption of d i can obtain ID i , PW i , and the hash key H2(ID i || PW i ) is used to encrypt the collected edge facility identity BS j and the public key PK j to generate D i ; thus it is ensured that the mobile terminal cannot access the encrypted information even in the case of attack. 3.The lightweight layered-blockchain privacy protection method for Internet of Vehicles according to claim 2, characterized in that, The step 2.4) comprises: 2.4.1) Initialization of the public key: taking as input the secret key S i , the password PW i and the biometric f i , when the given credentials are correct, the function verifies the validity of the current public key and generates the element P i that will be used in the transaction that has not yet been generated, Initiate(S i , PW i , f i )→(P i , Generate); 2.4.2) Generation of the public key: if the public key has expired, i.e. the time period λ has expired, the public key is regenerated i and the user P is in an invalid state 2.4.3) Validity verification of public key: According to the idea of randomly generating public key, no two consecutive public keys are the same, and the validity of the expired public key PK i and the newly generated public key is verified, if then it is considered valid, otherwise return to initialization again; 2.4.4) Initialization of the digital signature: the key pair {S i , PK i} required is obtained according to the public key random generation algorithm of steps 2.4.1) - 2.4.3); 2.4.5) Generation of digital signature: from given user identity ID i , private key S i , public key PK i and each transaction message m initiated by the user, the parameters F and D required for the digital signature are calculated respectively, and the signature Sig on the message m is generated i = (F, D); the generation process of the signature parameters takes into account the index information I t of the transaction; F and D are calculated as follows: I t = H3(m), F = (I t .H4(ID i ).P i )∈G1 D = (F.P i .z.S i )∈Z p Wherein, H(.) is a hash function, and z is a random number; 2.4.6) Verification of digital signature: if the bilinear pair function is satisfied, it is proved that the held signature is valid, the current held authentication transaction index and signature are received, otherwise the authentication transaction is rejected. 4.The lightweight layered-blockchain privacy protection method for Internet of Vehicles according to claim 1, wherein, The step 3) comprises: 3.1) Selection of multi-authority center: the holders of edge blockchain, i.e. all roadside unit nodes, are regarded as a candidate set of multi-authority center, and n nodes are selected from the candidate set to form an authority center according to random probability each time, the authority center is divided into authorized nodes and supervision nodes, the authorized nodes are responsible for initialization and generation of attribute key SK, and the supervision nodes are responsible for review of the work of the authorized nodes and review of the attribute set of the user; 3.2) Joint generation of attribute key by the selected multiple authorized nodes; 3.3) Introduce linear access structure LSSS in the ciphertext, let ap = (A, p, T) represent an access policy, where A is a secret matrix of l x n, p is a function that maps the attributes in the access policy to the attribute sequence values in the attribute universe, T = {a ρ(1) ,...,a ρ(l)} is the set of attribute values; randomly select a vector where sv is the secret value to be shared, denoted as the ith row vector of the access policy matrix A, calculate as the secret share value of each attribute p(x) in the access policy; if {w x} x∈A is a set of recovery coefficients, then there is ρ(x)∈A w x A x = (1, 0,..., 0), so that the secret share value can be recovered.

5. The lightweight layered-blockchain privacy protection method for Internet of Vehicles according to claim 4, characterized in that, The step 3.2) specifically includes: 3.2.1) A certain authorized node in the candidate set of multi-authority center selects a random number t to regenerate a new key, which is used for finally generating the attribute key of the user, and the random number t is protected by using the public key of the user, the newly generated key and the encrypted random number t are stored in the edge blockchain; 3.2.2) Another authorized node in the candidate set of multi-authority center uses the ciphertext generated by the random number t to encrypt and encapsulate the hash value of the attribute set of the user, so as to prevent the generation of attribute key by using the attribute set that does not match the user; 3.2.3) At the user end, the encrypted attribute set is decrypted by using the private key of the user, so as to judge whether the user matches the attribute set, if the matching is successful, the attribute key of the user is generated by using the newly generated key.

Citation Information

Patent Citations

  • Internet of Vehicles privacy protection trust model based on block chain

    CN110300107A

  • LBS privacy protection method in car networking sparse user environment

    CN115529150A