Vehicle identity management method, device, equipment and medium
The first type of pseudonym is obtained through vehicle registration, the second type of pseudonym is generated, and the cloud pseudonym management system is used for activation and replacement, solving the problem of massive pseudonym supply and multi-pseudonym witch attacks, realizing the automated and transparent management of pseudonym, and improving the user's privacy protection strength.
Patent Information
- Application Number
- CN202510105681.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The existing technology is difficult to effectively solve the problem of witch attacks faced by massive pseudonyms and multiple pseudonyms, and it is impossible to realize the automated and transparent management of pseudonyms, which affects the intensity of user privacy protection.
The first type of pseudonym distribution request certificate is obtained through vehicle registration, and the pseudonym authentication center generates the first type of pseudonym and sends it to the vehicle end. The vehicle end uses the first type of pseudonym to generate any number of second type of pseudonym and corresponding keys. The cloud pseudonym management system is used to activate and replace the second type of pseudonym, and record is saved to the blockchain to realize the automated management and transparency of pseudonym.
The problem of massive pseudonym supply and multiple pseudonym witch attacks was solved, and the automated and transparent management of pseudonym was realized, which improved the user's privacy protection intensity.
Smart Images

Figure CN119945783A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a vehicle identity management method, device, equipment and medium. Background Art
[0002] At present, in the related art, a proxy server is set to collect and summarize pseudonym applications, and then the pseudonym applications are shuffled and sent to PCA (Pseudonym Certificate Authority, pseudonym certification center). PCA cannot effectively associate the issued pseudonym with the vehicle used, realizing the irrelevance of the pseudonym, further improving the privacy protection strength of the vehicle, and adopting a pre-allocation strategy, the system pre-allocates the second type of pseudonym to be used for each vehicle, and issues it to the vehicle for storage and use in sequence at one time. In order to avoid the witch attack of multiple pseudonyms, a solution with non-overlapping validity periods of different pseudonyms is adopted, and the pseudonym validity period is fixed and the replacement is restricted. If the pseudonym validity period is shortened (such as a few minutes), a vehicle needs about 300,000 pseudonyms a year, which is a huge number, and the waste and expense are huge.
[0003] From the above, it can be seen that how to solve the problem of massive pseudonym supply and Sybil attacks faced by multiple pseudonyms, realize automated and transparent management of pseudonyms, and improve the strength of user privacy protection are issues to be solved in this field. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a vehicle identity management method, device, equipment and medium, which can solve the problem of massive pseudonym supply and Sybil attack faced by multiple pseudonyms, realize automatic pseudonym management, and improve the strength of user privacy protection. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a vehicle identity management method, comprising:
[0006] A first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition;
[0007] Obtaining a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, performing a system authorization check and a legitimacy verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization check and the legitimacy verification pass, setting the second-type pseudonym as activated, and generating a relevant activation certificate;
[0008] When the second-category pseudonym replacement request sent by the vehicle, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, security authentication is performed on the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
[0009] Optionally, the obtaining of the first type of pseudonym distribution request credential through vehicle registration, and the pseudonym authentication center registering the vehicle and generating the first type of pseudonym based on the first type of pseudonym distribution request credential, include:
[0010] Using a registration agency to distribute a vehicle license plate and a corresponding first-category pseudonym application certificate based on the registration request and the real registration information to complete vehicle registration and obtain the first-category pseudonym application request certificate for the vehicle;
[0011] Use the first-class pseudonym application certificate to apply for a first-class pseudonym distribution request from the pseudonym authentication center, so that the pseudonym authentication center randomly generates a first-class pseudonym and a corresponding key pair based on the first-class pseudonym distribution request.
[0012] Optionally, sending the first type of pseudonym to the vehicle end so that the vehicle end generates any number of second type of pseudonyms and corresponding keys according to the first type of pseudonym and using a certificateless signing method, includes:
[0013] The first-category pseudonym including its request number, quantity, starting validity period, and verification credential is sent to the vehicle end, so that the vehicle end adopts a certificateless signing method according to the first-category pseudonym, utilizes a secret sharing mechanism to generate any number of second-category pseudonyms according to preset second-category pseudonym generation rules and non-association rules, utilizes the key corresponding to the first-category pseudonym as a partial private key, and randomly generates a secret value, generates a signature key based on the partial private key and the secret value, generates a public key for verifying the signature using the second-category pseudonym and the secret value, and generates a key corresponding to the second-category pseudonym using the signature key and the public key for verifying the signature.
[0014] Optionally, the using of the cloud-based pseudonym management system and performing system authorization inspection and legitimacy verification on the second type of pseudonym based on the second type of pseudonym activation request includes:
[0015] The cloud-based pseudonym management system is used to perform authorization authentication, pseudonym compliance verification and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
[0016] Optionally, the vehicle identity management method further includes:
[0017] Use the pseudonym resolution system to conduct global malicious behavior supervision on all second-category pseudonyms;
[0018] When there is a second-category pseudonym for malicious behavior, the second-category pseudonym for malicious behavior is determined, and the second-category pseudonym for malicious behavior is decrypted to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, the first-category pseudonym is parsed to obtain the true identity of the vehicle, and a pseudonym revocation request is generated.
[0019] Optionally, the vehicle identity management method further includes:
[0020] When the cloud-based pseudonym management center obtains the pseudonym revocation request, all issued first-category pseudonyms corresponding to the real identity of the vehicle are determined based on the pseudonym revocation request, and all issued first-category pseudonyms are revoked.
[0021] Optionally, the step of saving the corresponding replacement record to the blockchain includes:
[0022] The second-category pseudonym activation data and the second-category pseudonym replacement data are stored in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
[0023] In a second aspect, the present application discloses a vehicle identity management device, comprising:
[0024] A pseudonym generation module, used to obtain a first-class pseudonym distribution request credential through vehicle registration, a pseudonym authentication center performs vehicle registration and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys according to the first-class pseudonym and adopts a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition;
[0025] a second-type pseudonym activation module, configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, perform system authorization inspection and legality verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization inspection and legality verification pass, set the second-type pseudonym as activated and generate a relevant activation certificate;
[0026] The second-category pseudonym replacement module is used to perform security authentication on the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the second-category pseudonym information currently activated, and if the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the second-category pseudonym information currently activated is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
[0027] In a third aspect, the present application discloses an electronic device, comprising:
[0028] Memory, used to store computer programs;
[0029] The processor is used to execute the computer program to implement the aforementioned vehicle identity management method.
[0030] In a fourth aspect, the present application discloses a computer storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the vehicle identity management method disclosed above are implemented.
[0031] It can be seen that the present application provides a vehicle identity management method, including obtaining a first-class pseudonym distribution request credential through vehicle registration, a pseudonym authentication center registering a vehicle and generating a first-class pseudonym based on the first-class pseudonym distribution request credential, and sending the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; obtaining a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end, using a cloud-based pseudonym management system and based on the second-class pseudonym The second-category pseudonym activation request is subjected to system authorization check and legality verification on the second-category pseudonym. If the system authorization check and legality verification are passed, the second-category pseudonym is set to be activated, and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the second-category pseudonym information currently activated are obtained, a security authentication is performed on the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced. If the security authentication is passed, the second-category pseudonym currently in use is set to invalid, and the second-category pseudonym information currently activated is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first-class pseudonym to register the vehicle and generate a first-class pseudonym with a validity period that meets the preset long-term condition, and sends the first-class pseudonym to the vehicle end so that the vehicle end can generate any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second-class pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legality verification on the second-class pseudonym. If the system authorization inspection and legality verification pass, the second-class pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and superviseability. When a request for changing a second-category pseudonym is obtained, security authentication is performed on the request for changing a second-category pseudonym, the activated second-category pseudonym, and the second-category pseudonym information to be changed. If the security authentication is passed, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism is used to solve the Sybil attack problem faced by multiple pseudonyms. Vehicles can change an unlimited number of pseudonyms on demand, and save the corresponding change records to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0033] Figure 1 A flow chart of a vehicle identity management method disclosed in this application;
[0034] Figure 2 A flowchart of vehicle registration and first-category pseudonym distribution disclosed in this application;
[0035] Figure 3 A flow chart of a certificateless signature scheme disclosed in this application;
[0036] Figure 4 A second type of pseudonym activation flow chart disclosed in this application;
[0037] Figure 5 A flow chart of cross-domain vehicle pseudonym management disclosed in this application;
[0038] Figure 6 A pseudonym-based connected car data privacy protection flow chart disclosed in this application;
[0039] Figure 7 A complete pseudonym full-cycle management flow chart disclosed in this application;
[0040] Figure 8 This is a schematic diagram of the structure of a vehicle identity management device disclosed in this application;
[0041] Fig. 9 A structural diagram of an electronic device provided for this application. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] At present, in the related art, a proxy server is set to collect and summarize pseudonym applications, and then the pseudonym applications are shuffled and sent to PCA (Pseudonym Certificate Authority, pseudonym certification center). PCA cannot effectively associate the issued pseudonyms with the vehicles used, realizing the irrelevance of pseudonyms, further improving the privacy protection strength of vehicles, and adopting a pre-allocation strategy. The system pre-allocates the second type of pseudonyms to be used for each vehicle, and issues them to the vehicles for storage and use in sequence at one time. In order to avoid the witch attack of multiple pseudonyms, a solution is adopted in which the validity periods of different pseudonyms do not overlap, and the validity period of pseudonyms is fixed and the replacement is restricted. If the validity period of the pseudonym is shortened (such as a few minutes), a vehicle needs about 300,000 pseudonyms a year, which is a huge number, and the waste and cost are huge. As can be seen from the above, how to solve the witch attack problem faced by massive pseudonym supply and multiple pseudonyms, realize the transparent management of pseudonym automation, and improve the privacy protection strength of users are problems to be solved in this field.
[0044] See also Figure 1 As shown, the embodiment of the present invention discloses a vehicle identity management method, which may specifically include:
[0045] Step S11: Obtain a first-class pseudonym distribution request credential through vehicle registration, and a pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition.
[0046] In this embodiment, a registration agency distributes a vehicle license plate and a corresponding first-class pseudonym application certificate based on the registration request and the real registration information to complete vehicle registration and obtain the first-class pseudonym application request certificate of the vehicle; the first-class pseudonym application certificate is used to apply for a first-class pseudonym distribution request to a pseudonym authentication center, so that the pseudonym authentication center randomly generates a first-class pseudonym and a corresponding key pair based on the first-class pseudonym distribution request, and sends the first-class pseudonym including the request number, quantity, starting validity period, and verification certificate of the first-class pseudonym to the vehicle end, so that the vehicle end adopts a certificateless signature method according to the first-class pseudonym, uses a secret sharing mechanism to generate any number of second-class pseudonyms according to preset second-class pseudonym generation rules and non-association rules, and uses the key corresponding to the first-class pseudonym as a partial private key, and randomly generates a secret value, generates a signature key based on the partial private key and the secret value, generates a public key for verifying the signature using the second-class pseudonym and the secret value, and uses the signature key and the public key for verifying the signature to generate a key corresponding to the second-class pseudonym.
[0047] The process of vehicle registration and first-class pseudonym distribution is as follows: Figure 2 As shown, the specific steps can be summarized as follows:
[0048] 1. The new vehicle registers its real identity with the vehicle registration agency and obtains a request certificate for the first-class pseudonym; the vehicle uses the request certificate to request a certain number of first-class pseudonyms and corresponding keys from the vehicle first-class pseudonym distribution center;
[0049] 2. The vehicle first-class pseudonym center generates a first-class pseudonym, a corresponding key and authorization verification materials for the requesting vehicle;
[0050] 3. The vehicle first-class pseudonym center sends the authorization verification materials corresponding to the vehicle first-class pseudonym to the first-class pseudonym credential center for storage, so as to facilitate later query and verification in the cloud;
[0051] 4. The vehicle first pseudonym center sends the first pseudonym and the corresponding key to the requesting vehicle;
[0052] 5. The vehicle generates a second type of pseudonym and a corresponding signature key and verifies the signature key based on the first type of pseudonym and the corresponding key;
[0053] 6. The vehicle requests the cloud-based vehicle identity management system to activate the generated second pseudonym;
[0054] 7. The cloud vehicle identity management system queries the first type of pseudonym storage center for authorization information of the pseudonym to be activated;
[0055] 8. After the authorization is passed, the cloud-based vehicle identity management system verifies the legitimacy of the pseudonym to be activated; after passing, it confirms that the pseudonym has been successfully activated and the pseudonym can be put into use.
[0056] New vehicles entering the network must be registered. During registration, the real information of the vehicle and the owner is recorded. The vehicle registration agency RCA distributes a vehicle license plate VID to the registered vehicle and generates n corresponding pseudonym requests req for the vehicle. u,i , i = 1, 2, ..., n, and the corresponding verification credential token u,i , i = 1, 2, ..., n, registration (VID u ,req u,i , token u,i ), then (req u,i , token u,i ) is sent to the vehicle being registered.
[0057] Vehicle use (req u,i , token u,i) submits a first-class pseudonym request to the first-class pseudonym generation center, and the first-class pseudonym generation center uses (req u,i , token u,i ) to perform security verification. After passing, for each request req u,i , i = 1, 2, ..., n generates a first-class pseudonym and a corresponding key. The specific generation method is: the first-class pseudonym LPID_SET u ={LPID u,1 , LPID u,2 , ..., LPID u,n}, first class pseudonym LPID u,i represents the valid first-class pseudonym of vehicle u at time i, and the first-class pseudonym generation center is registered (req u,i , LPID u,i ). Each first-class pseudonym (req u,i , LPID u,i ) corresponds to a public key and a private key (pk u,i ,sk u,i ), corresponding to a partial private key and an authorization verification credential. Then, the first-class pseudonym generation center distributes all first-class pseudonyms and corresponding key materials to the requesting vehicle.
[0058] Among them, the first type of pseudonym distribution request format (first type of pseudonym request number, quantity, starting validity period, verification certificate (cannot be reused)). Distribution information format (first type of pseudonym request number, first type of pseudonym, validity period, certificate, signature).
[0059] In this embodiment, the second type of pseudonym is generated and issued by the vehicle itself, but the second type of pseudonym must meet certain requirements, including: the second type of pseudonym must be obtained by obtaining a valid first type of pseudonym, and the system authorization, and the generated second type of pseudonym must be related to the current valid first type of pseudonym, so that the identity of the second type of pseudonym can be resolved when necessary. In other words, the related first type of pseudonym can be restored from the second type of pseudonym. However, the first type of pseudonym cannot appear directly in the second type of pseudonym to ensure the uncorrelation of the second type of pseudonym.
[0060] Each first-class pseudonymous LPID u,i All have a certain validity period. For the first type of pseudonym LPID within the validity period u,i , the vehicle can generate a number of second-class pseudonyms In order to meet the requirements for generating the second type of pseudonym, this application uses a secret sharing mechanism to generate the second type of pseudonym. The specific method is as follows:
[0061] 1. Set s=LPID u,i Shared secret, construct polynomial Where a1 is a random value. For the function value corresponding to the non-zero horizontal coordinate of the polynomial, the corresponding commitment is generated as
[0062] 2. Generate two second-class pseudonyms each time, one as a new second-class pseudonym A pseudonym as proof of identity
[0063] 3. Use Feldman VSS (a verifiable secret sharing scheme) to verify the association between the second type of pseudonym and the first type of pseudonym.
[0064] After generating the second type of pseudonym, generate a key corresponding to the second type of pseudonym. The generated second type of pseudonym must correspond to a private key for signing and a public key for verifying the signature. Different from the traditional public key infrastructure (PKI) digital certificate scheme, this application adopts a certificateless signature scheme. The certificateless signature scheme is a special identity-based signature scheme. Its public key does not require a digital certificate and avoids the key escrow problem. In order to generate a certificateless signature key corresponding to a short-term signature, this application proposes a message authentication using a certificateless signature scheme that can resist Type I and Type II attacks. The signature private key of the vehicle's second type of pseudonym consists of two parts. One part is the key corresponding to the first type of pseudonym as a partial private key in the certificateless signature scheme, and the other part is a secret value randomly generated by the vehicle module. The partial private key and the secret value generate a signature private key, and the second type of pseudonym and the secret value generate a public key for verifying the signature. The process of the certificateless signature scheme is as follows: Figure 3 As shown, the description is as follows:
[0065] Setup: Given a parameter k, KGC (key generation center) generates system parameters and master keys according to the following steps: KGC generates a bilinear group (G1, G T ), where |G1|=|G T |=p, p is a prime number, and p≥2 k , k is the system security parameter. e is the bilinear mapping G1×G1→G T . Select a master key for the secure hash function KGC Select a random element And calculate the master public key P pub =s·P, KGC publishes system parameters params={G1, G T ,p,e,P,P pub , H0, H1}.
[0066] PartialPrivateKeyExtract: For a specific date vehicle select KGC for each LPID u,i , choose a random number set up
[0067] SetSecretValue: User sets a short-term pseudonym Pick a random number as a secret value.
[0068] SetPrivateKey: Set the signature private key to
[0069] SetPublicKey: User ID calculation Its public key
[0070] Sign: For message m, The user calculates the signature σ = (h, W):
[0071] where the random number r∈Z p ;
[0072] (Complete the key operation of signing).
[0073] Verify: Given a user message / signature pair (m, σ = (h, W)), user public key Verify the equation Is it true? If so, the signature is correct, otherwise the signature is rejected (message, ID, signature, user public key and master public key).
[0074] Step S12: Obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, and use the cloud-based pseudonym management system to perform system authorization inspection and legality verification on the second-type pseudonym based on the second-type pseudonym activation request. If the system authorization inspection and legality verification pass, the second-type pseudonym is set to be activated, and a relevant activation certificate is generated.
[0075] In this embodiment, after obtaining the second-type pseudonym activation request sent by the vehicle end, the cloud-based pseudonym management system is used to perform system authorization verification and legality verification on the second-type pseudonym based on the second-type pseudonym activation request; the activation verification includes authorization authentication, pseudonym compliance verification and signature authentication. If the system authorization verification and legality verification pass, the second-type pseudonym is set to activated and a relevant activation certificate is generated.
[0076] In this embodiment, the newly issued pseudonym for the vehicle must be activated by CPM (Cloud Pseudonym Management System) before it is put into use. The second type of pseudonym activation process is as follows: Figure 4As shown, CPM performs a complete authentication on the pseudonym to be activated, and the authentication process includes pseudonym authorization authentication, pseudonym compliance check and signature verification. For the pseudonym to be activated, the authorization certificate must be provided first for authorization authentication.
[0077] The issuer of the first-class pseudonym must also construct a verifiable proof for the vehicle, which proves that the vehicle's self-signed pseudonym has obtained a valid system authorization. The accumulator function can give the set U, which is the set of all first-class pseudonyms, V, which is the set of used first-class pseudonyms, and x c =LPID u,i is the pseudonym to be activated currently, W is the set of other unused first-class pseudonyms, and its authorization method is to verify x c ∈UV. The verification method adopts the password accumulator method. For the first type of pseudonym LPID u,i , its authorization token is divided into two parts (proof, token) = (acc s (W), acc x (UV)), through e(.) and group element g s It can be proved that the process uses bilinear mapping, and the specific method of verification is: After passing, the vehicle can confirm that (proof, token) = (acc s (W), acc x (UV)) is correct.
[0078] When activating a vehicle pseudonym, you need to provide proof of authorization and present it to the Pseudonym Management Center (PMC) (LPID u,i ,proof u,i , token u,i ). PMC uses token = acc x (UV) to query. If the content is in the current query table, it means that there is no authorization. Otherwise, authorization verification is performed. If the verification fails, the authorization is not passed. No authorization or authorization verification failure will cause the second type of pseudonym to be unable to be activated.
[0079] Attached to the request, g s Can be pre-provided as a public parameter or a one-time parameter, acc s (U) As a control of whether the pseudonym set is valid, its authenticity is guaranteed by a digital signature. Revoking the pseudonym set can delete the acc s (U), the subsequent pseudonyms belonging to this set will no longer be activated and used. Since the vehicle revokes a used pseudonym each time, the vehicle can automatically update the authorization credentials, avoiding a large amount of credential generation and transmission overhead.
[0080] The pseudonym generation center then updates the authorization token:
[0081] The pseudonym compliance check is to make sure that the short-term pseudonym to be activated contains the first type of pseudonym verification, that is, check Whether the requirement contains a secret sharing shadow of a valid first-class pseudonym.
[0082] verify: If the verification passes, the shadow is correct.
[0083] use and Perform shared secret recovery, assuming the recovered secret is s′, verify Verification passed indicates that the shadow contains a valid first-class pseudonym. Then the cloud records This is convenient for restoring the first-class pseudonym LPID during later pseudonym resolution. u,i .
[0084] Then, verify The correctness of the corresponding public key.
[0085] Vehicle pair The corresponding public key is self-signed, and a signature verification is required when the pseudonymous identity is activated.
[0086]
[0087] After the verification of the above steps, it is proved that the pseudonym is authorized by the system, the pseudonym construction is compliant, and the pseudonym and the key are consistent. The system can activate the pseudonym, the system records the activation of the pseudonym, and allows the activated pseudonym to enter the next use or replacement stage.
[0088] The identity management system of the present application uses a pseudonym generation mechanism of a hierarchical structure, including the real identity VID of the vehicle, the first type of pseudonym LPID and the second type of pseudonym SPID. The first type of pseudonym LPID is used for the system to authorize the vehicle to issue a pseudonym by itself, and is also used as a key connection for pseudonym resolution. The second type of pseudonym SPID is used for the signature of the vehicle to send information, ensuring the authenticity and non-tamperability of the message. Each first type of pseudonym can have a relatively long validity period (such as one day), and the validity period of the second type of pseudonym can be as short as a few minutes. VID and LPID are generated and managed by a credential management system based on VPKI. The system generates the first type of pseudonym required for a period of time (one year or three years) for the vehicle according to the SMCS mechanism, distributes it to the vehicle in a secure manner in an encrypted and packaged manner, and the vehicle stores it in the HSM (hardware security module) module in the OBU (The Onboard Units). The second type of pseudonym is generated and managed by the user in a self-agent manner. The second type of pseudonym must be embedded or associated with the currently valid first type of pseudonym issued by the system. The system can derive the first type of pseudonym through the second type of pseudonym, and resolve or revoke the vehicle through the first type of pseudonym. In message authentication, the vehicle signs and verifies the message based on the second-class signature key. To ensure the location privacy of the vehicle, the second-class signature automatically changes the key in a timely manner according to the pseudonym change strategy.
[0089] Step S13: When the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
[0090] In order to prevent the problem of witch attacks, the system of this application must prohibit vehicles from using multiple second-class pseudonyms at the same time. Although vehicles can generate multiple second-class pseudonyms, the pseudonyms must be activated by the system before they can be used. The system ensures that all vehicles have only one valid second-class pseudonym at a time. When a pseudonym is changed, it needs to go through a series of security verifications. The newly activated pseudonym can replace the currently used pseudonym, and the replaced pseudonym will be invalid immediately. The changed pseudonym operations and data are recorded in the pseudonym log server that cannot be changed. Other users can query the validity of the pseudonym to check whether the pseudonym is valid.
[0091] The basic activation and replacement pseudonym request format is as follows:
[0092]
[0093] new After activation, confirm the second type of pseudonym to be replaced Therefore, we need to ensure the legitimacy of the second type of pseudonym to be replaced. The steps are as follows:
[0094] 1. Confirmation is currently using a pseudonym;
[0095] 2. Use separately and Recover the shared secret and verify whether the first-class pseudonyms recovered by the two are consistent. The consistency will ensure that the new pseudonym and the second-class pseudonym to be replaced belong to the same vehicle.
[0096]
[0097] 3. Verify the signature capability of the replaced pseudonym:
[0098]
[0099] After passing this check, it means that the vehicle has the signature private key of the replaced pseudonym and is indeed the real owner of the replaced pseudonym. In this way, when a new first-class pseudonym is used for the first time to authorize a new pseudonym, it does not need to replace the pseudonym in use. At other times, when a new pseudonym is enabled, it must replace an existing pseudonym, and the replaced pseudonym will be invalidated immediately. This mechanism will ensure that although the vehicle can generate several valid second-class pseudonyms, only one of them can be enabled at the same time. This effectively avoids the problem of using multiple identity witch attacks.
[0100] In this embodiment, after the second-type pseudonym is replaced, the second-type pseudonym activation data and the second-type pseudonym replacement data are stored in the blockchain so that the blockchain can perform transparent management and pseudonym validity query. The blockchain data can provide public audit support for cloud pseudonym management behavior. The system also provides validity query or certification for the vehicle's currently used second-type pseudonyms in a whitelist manner.
[0101] The process of cross-domain vehicle pseudonym management in this application is as follows Figure 5As shown. Due to the mobility of vehicles, vehicles may travel to places other than their territories. The pseudonyms of vehicles in other places involve cross-domain vehicle pseudonym management. In the technical solution of this application, the pseudonyms of cross-domain vehicles are still managed by the territorial vehicle management agency. Although the vehicles are located in different regions, the vehicle pseudonyms can still be generated and issued by the vehicles themselves. The activation of new pseudonyms is still managed by the territories through the network, and the processing method is consistent with the local processing method. After the new pseudonym is activated and put into use, the system will provide a validity certificate. Vehicles entering other places can provide validity certificates for their pseudonyms. After verification by the vehicle management agency in other places, the validity of their pseudonyms will be recognized. In order to increase the security of the pseudonym system, for the pseudonyms of newly entered vehicles in other places, the pseudonym validity can also be queried from the location of the vehicle. The territorial vehicle management agency will provide the latest information and certificates on the validity of the pseudonym. The certificate can be publicly verified and traced for audit.
[0102] Combined with PKI (Public Key Infrastructure) and the verifiable credential technology of vehicle digital identity, cross-domain and remote pseudonym management is realized. Combined with vehicle pseudonyms, channel technology is used to store vehicle data on the chain and store off-chain industrial data, so as to achieve privacy protection and effective use of vehicle data. Through the existence of on-chain data, the authenticity of off-chain data evidence is facilitated.
[0103] To ensure the transparency of pseudonym management and reduce the level of trust in CA (Certificate Authority), the system is implemented using a practical alliance chain fabric, which is composed of different organizations (vehicle management department, traffic police, traffic supervision, insurance, vehicle service provider), and practical blockchain technology to achieve decentralized transparent management of vehicle identity; on-chain data is combined with off-chain data, and on-chain data is used for pseudonym activation, pseudonym replacement, public audit, and pseudonym information query; off-chain data is key and credential information, and other non-confidential but large-volume information; to ensure system efficiency and real-time performance, a permission chain is used to provide security for on-chain data and provide data access to the outside world; vehicles submit transaction data in the form of applications, and peers (nodes) submit transaction data, including pseudonym activation, replacement, query, audit, etc.; on-chain data is added and modified by smart contracts, and smart contracts are determined by relevant operating protocols.
[0104] The cryptographic accumulator used in transparent pseudonym management has two important properties: (1) for a specific element, the accumulator can have a constant membership proof size and computational cost; (2) without knowing s, the relevant credentials cannot be forged. Based on these two characteristics of the accumulator, the accumulator function value of the vehicle's second-class pseudonym and the corresponding public key is used as the accumulator value, and a pseudonym validity credential is constructed at the same time, which can be publicly verified. The accumulator value of the current valid pseudonym set can be stored in the blockchain, which is convenient for the system or other vehicles to publicly verify. The pseudonym validity credential is generated by the pseudonym management system and issued to the vehicle. Since the pseudonym is in a dynamic change process, it is necessary to dynamically adjust the current valid pseudonym set, and adjust the accumulator value and pseudonym validity credential at the same time.
[0105] The relevant accumulator algorithm is as follows:
[0106] pp←Acc.Setup(1 λ ): System initialization, based on the system security parameter λ, generate system public parameters, let bp = {p, G1, G2, G T , e, g1, g2}, output
[0107] A X ←Acc.Commit pp (X): Generate the accumulator value of the pseudonym set, input pseudonym set X = {x1, x2..., x n}, X(s) = Π x∈X (s+x), output
[0108] A′ X ←Acc.Add pp (A X , X, I): The accumulator value of the new set generated after incorporating the new pseudonym set, where X←X∪I, output
[0109] A′ X ←Acc.Del pp (A X , X, I): The accumulator value of the new set after deleting the pseudonymous subset, where X←XI, output
[0110] π y ←Acc.MemProve pp (X, y): Generate a member's qualification certificate, input y∈X, output
[0111] {0, 1}←Acc.MemVerifypp (AX, y, π y ): Membership verification, input pseudonym y∈X and qualification proof π y , if the verification is successful, output 1, otherwise output 0.
[0112] In addition, the vehicle identity management method proposed in the present application also includes: using a pseudonym resolution system to perform global malicious behavior supervision on all second-category pseudonyms; when there is a second-category pseudonym for malicious behavior, determining the second-category pseudonym for malicious behavior, and decrypting the second-category pseudonym for malicious behavior to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, resolving the first-category pseudonym to obtain the true identity of the vehicle, and generating a pseudonym revocation request.
[0113] This application proposes a privacy-enhanced pseudonym resolution technology that can achieve global malicious behavior monitoring for all pseudonyms: when a pseudonym is reported to have abnormal behavior or malicious behavior, MA (pseudonym resolution system) performs global malicious behavior detection; after determining the malicious behavior, the corresponding first-class pseudonym LPID is derived based on the current second-class pseudonym SPID decryption, and then the pseudonym is resolved to obtain the true identity of the vehicle for accountability processing.
[0114] In order to prevent the real identity behind the pseudonym from being resolved or leaked without reason, pseudonym resolution needs to have sufficient reasons. The resolution cannot be performed by a single department, but must be performed jointly by different departments. This application adopts a privacy enhancement method similar to the "separation of powers" for pseudonym resolution. The pseudonym resolution agency jointly with the cloud management center, the first type of pseudonym generation center and the vehicle registration agency resolves the pseudonyms with malicious behavior, obtains the corresponding vehicle real identity VID, and completes the pseudonym resolution.
[0115] Pseudonym resolution process:
[0116] Pseudonym resolution agency and cloud: This is convenient for restoring the first-class pseudonym LPID during later pseudonym resolution. u,i ;
[0117] Pseudonym resolution agencies and first-class pseudonym generation centers: through LPID u,i Find out (req u,i , LPID u,i ), and we get req u,i .
[0118] Pseudonym resolution agency and vehicle registration agency: through req u,i ,(VID u ,req u,i ) Look up the table to get the real identity VID of the vehicle u .
[0119] Data is recorded during each pseudonym resolution process to facilitate subsequent audits and privacy leak reviews.
[0120] The vehicle identity management method also includes: when the cloud-based pseudonym management center obtains the pseudonym revocation request, all issued first-class pseudonyms corresponding to the real identity of the vehicle are determined based on the pseudonym revocation request, and all issued first-class pseudonyms are revoked.
[0121] For pseudonyms with malicious behavior, after the pseudonym is resolved, the pseudonym revocation process must be carried out. The pseudonym revocation proposed in this application is different from the traditional method based on the revocation list, but is based on the whitelist method. When the pseudonym is removed from the valid pseudonym table in the cloud, it means that the pseudonym is revoked. After the current pseudonym is revoked, the newly generated pseudonym will no longer be added or replaced by the pseudonym. When the pseudonym is revoked, all the corresponding first-class identity LPIDs that have been issued are obtained according to the real identity VID of the vehicle, and the authorization certificates corresponding to these first-class identities are revoked. For the existing pseudonyms, it is no longer possible to obtain valid pseudonym certificates in use. The pseudonyms will be regarded as revoked or invalid pseudonyms and cannot be used for subsequent secure communications. These first-class identities are revoked, and the corresponding authorization certificates stored in the long-term pseudonym certificate center are deleted. The vehicle will no longer be able to activate a new pseudonym, thereby completing the revocation of the vehicle pseudonym. For the existing pseudonyms, it is no longer possible to obtain valid pseudonym certificates in use. The pseudonyms will be regarded as revoked or invalid pseudonyms and cannot be used for subsequent secure communications. To prevent the Sybil attack, the system must prohibit vehicles from using multiple second-class pseudonyms at the same time. Although vehicles can generate multiple second-class pseudonyms, the pseudonyms must be activated by the cloud pseudonym management system before they can be used. The cloud pseudonym management system will ensure that all vehicles have only one valid second-class pseudonym at a time. When a pseudonym is changed, a series of security verifications are required. After applying for activation to the cloud pseudonym management system, the new pseudonym can replace the current pseudonym in use, and the replaced pseudonym will become invalid immediately. The changed pseudonym operation and data are recorded in the unchangeable pseudonym log server. Other users can query the validity of the pseudonym to check whether the pseudonym is valid. In order to ensure the transparency and auditability of pseudonym operations, blockchain is introduced to record the relevant operations of pseudonym management. Pseudonym operations are automatically executed by smart contracts, and relevant data are recorded in the blockchain. In order to improve system efficiency, the system records data in two parts: on-chain and off-chain. On-chain data is non-deletable blockchain ledger data, which is convenient for operation and data auditing. Off-chain data is controlled by on-chain data, providing efficient query and log functions.
[0122] This application proposes a pseudonym-based connected car data privacy protection technology. Due to the mobility of the vehicle, the vehicle may travel to a different place from the place of residence. At this time, the activation of the vehicle pseudonym is the responsibility of the local vehicle management system, and the pseudonym management operation is also recorded in the local blockchain. At this time, the resolution of the vehicle pseudonym requires the cooperation of the local vehicle management. The vehicle's driving data is usually uploaded to the manufacturer's data center for storage to facilitate vehicle fault monitoring and accident evidence collection. In this way, the authenticity and non-tampering of the data must be solved. In addition, since these data contain the vehicle's spatiotemporal information and contain sensitive information of many users, it is necessary to propose a complete method to solve these problems.
[0123] The patented replaceable multiple pseudonyms issued by the vehicle itself undoubtedly provides a better technical approach for data privacy protection of connected cars. The vehicle driving data relies on the pseudonym identity of the vehicle. Since different pseudonyms are unrelated, unlimited multiple pseudonym replacement avoids data aggregation on the data storage platform. Relevant vehicle data can still be used for vehicle status monitoring, but it is difficult to perform correlation analysis with user-sensitive spatiotemporal data. When the vehicle shows signs of failure, the manufacturer needs to contact or notify the vehicle. At this time, pseudonym resolution can be used, and the system can restore the vehicle's contact information through pseudonym resolution, which better solves the problem of data use and privacy protection. Specific solutions such as Figure 6 As shown:
[0124] 1. The vehicle uploads its driving data to the vehicle manufacturer’s data platform under a pseudonym;
[0125] 2. The vehicle manufacturer's data platform monitors the data and alerts the vehicle if an abnormality is found;
[0126] 3. The vehicle manufacturer data platform sends a pseudonym resolution request to the pseudonym resolution center, requesting the contact information of the vehicle corresponding to the pseudonym;
[0127] 4. After multiple parties cooperated, the pseudonym resolution was completed and the vehicle’s contact information was obtained;
[0128] 5. The manufacturer issues vehicle condition warnings or provides corresponding services.
[0129] In summary, the complete pseudonym full-cycle management process proposed in this application is as follows: Figure 7 As shown, including:
[0130] 1. The new vehicle shall register its real identity with the vehicle registration agency and obtain the first-class pseudonym certificate;
[0131] 2. The vehicle applies for a first-class pseudonym from the first-class pseudonym issuing agency, and the first-class pseudonym issuing agency distributes a first-class pseudonym set and related key materials to the vehicle;
[0132] 3. The first-class pseudonym issuing agency distributes the first-class pseudonym certificate to facilitate the pseudonym management center to verify the legal authorization of the pseudonym;
[0133] 4. The vehicle generates a short-term pseudonym and corresponding key as needed based on the valid first-class pseudonym;
[0134] 5. The vehicle requests the pseudonym management center to activate a new short-term pseudonym. After successful activation, it issues a pseudonym use or replacement request;
[0135] 6. The pseudonym management center checks and verifies the validity of pseudonyms through smart contracts;
[0136] 7. After the pseudonym validity verification is passed, the new pseudonym will be activated and the old pseudonym will be cancelled. All operations will leave traces on the blockchain data, and relevant operations will generate verifiable credentials for subsequent use or auditing;
[0137] 8. The new pseudonym is officially used. Vehicles can use the new pseudonym to sign messages. Other vehicles can use the public key corresponding to the pseudonym to verify the signed message and discard messages that fail the verification.
[0138] 9. The vehicle that receives the message queries the validity of the pseudonym, which can be done online or offline;
[0139] 10. The system also has a pseudonym resolution mechanism, which is responsible for recovering the real identity of the vehicle from the short-term pseudonym. The system can include a malicious behavior detection module, which performs pseudonym identity resolution and pseudonym revocation for vehicles confirmed to have malicious behavior;
[0140] The key technologies of the entire pseudonym management system are:
[0141] 1. Controllable vehicle self-issued pseudonym technology: The pseudonyms issued by the vehicle are supplied on demand, solving the problem of massive pseudonym supply based on central issuance, and providing a secure vehicle second-class pseudonym self-issued supply mechanism. Vehicles can replace an unlimited number of pseudonyms on demand. The core technology is to solve the compliance and controllability of pseudonyms, introduce the concepts of first-class pseudonyms and second-class pseudonyms, and use certificateless signatures. The first-class pseudonyms complete system authorization and pseudonym resolution and supervision, and the second-class pseudonyms are used for secure communication of vehicles. The core point is how to determine the compliance authorization of the self-issued second-class pseudonyms, the legitimacy of the generated pseudonyms, the activation and replacement methods of pseudonyms, the efficient query of pseudonyms, and the pseudonym revocation mechanism based on the whitelist.
[0142] 2. Transparent automatic pseudonym management technology: Use smart contracts to complete automated pseudonym management operations to avoid human intervention; use an accumulator-based method to leave traces of pseudonym management operations, and combine blockchain technology to achieve public auditability of operations, effective and transparent operations and supervision.
[0143] 3. Privacy-enhanced pseudonym resolution technology: Solve the Sybil attack problem faced by multiple pseudonyms through the pseudonym activation mechanism; leave traces of pseudonym operations, and store relevant credentials in the blockchain to facilitate auditing and restrict internal violations; use the separation of powers mechanism to conduct multi-party joint pseudonym resolution to enhance user privacy protection.
[0144] 4. Efficient cross-domain vehicle pseudonym query and verification technology: It can effectively manage the pseudonyms of vehicles across regions and solve the problem of multiple pseudonyms being valid in different regions.
[0145] 5. Pseudonym-based connected car data privacy protection technology: Vehicle driving data is usually uploaded to the manufacturer's data center for storage, which is convenient for vehicle fault monitoring and accident evidence collection. Using the self-issued multi-pseudonym system of this application, the vehicle driving data is uploaded using the vehicle pseudonym, making the data uploaded by the vehicle anonymous. At the same time, due to the use of multiple pseudonyms and the lack of correlation between different pseudonyms, user data can be exposed to big data correlation technology, which helps to protect user sensitive information. Manufacturers can still monitor the driving data of pseudonyms. If they need to contact the vehicle immediately in an emergency, they can also obtain the contact information of the owner corresponding to the pseudonym through pseudonym resolution. This is an effective method that takes into account both data utilization and privacy protection.
[0146] The advantages of this application are as follows:
[0147] In terms of pseudonym supply and management: a pre-allocation scheme is adopted, and the pseudonyms are issued once for storage and use in sequence. In order to avoid witch attacks with multiple pseudonyms, a solution with non-overlapping validity periods of different pseudonyms is adopted. The validity period of pseudonyms is fixed and the replacement is restricted. If the validity period of pseudonyms is shortened (such as a few minutes), a vehicle will need about 300,000 pseudonyms a year, which is a huge number, waste and cost. If the validity periods of different pseudonyms overlap, multiple pseudonyms may be valid at the same time, bringing the risk of witch attacks. In addition, vehicles can apply for multiple identities across domains, which makes it difficult to solve the problem of witch attacks. This application adopts a hybrid pseudonym supply method. The first type of pseudonyms are pre-allocated by the system, with a small number and a small distribution and storage burden. The second type of pseudonyms can be generated on demand, which can solve the problem of diffusibility caused by massive pseudonyms. Although there have been some hybrid schemes in the past, the group signature method is mainly used. For fast-moving vehicles, group management is difficult and the support of the road test unit RSU is required, which is not ideal for practicality. The hybrid solution of this application is based on certificateless signature and adopts a set of technologies to solve the management problems of the whole life cycle, such as Sybil attacks, authorization issues, pseudonym legitimacy issues, pseudonym replacement and resolution.
[0148] Integrated application of multiple mature technologies: In view of the complexity of the full-cycle management of vehicle pseudonyms, this application comprehensively applies multiple existing technologies. In the allocation and resolution of the first type of pseudonyms, a three-power separation mechanism is adopted to enhance the system's ability to prevent privacy leakage; a certificateless signature scheme is used to implement the core technology of credential management of the second type of pseudonyms, which not only eliminates the key escrow problem, but also enables the vehicle to have the ability to independently generate identity and keys; in identity construction and verification, secret sharing and password accumulators are cleverly used to complete identity authorization and compliance verification; blockchain and smart contract technology are combined to achieve transparency and auditability of vehicle identity; the whitelist pseudonym revocation technology is used, which has high revocation efficiency compared with the traditional blacklist method.
[0149] In terms of the balance between intelligent networked vehicle data utilization and privacy protection: At present, the driving data of intelligent networked vehicles will be transmitted to platforms such as vehicle manufacturers. Vehicle big data helps to monitor vehicle status, train and improve intelligent driving systems, provide better services, determine vehicle accident responsibility and many other uses. There are problems of excessive data collection and privacy leakage. As privacy awareness and the harm of privacy leakage increase, more technologies are needed to find a balance between the two. The multi-pseudonym networked vehicle data privacy protection technology proposed in this application uses the self-issued multi-pseudonym system of this application, and uses the vehicle pseudonym to upload vehicle driving data, so that the data uploaded by the vehicle is anonymized. At the same time, due to the use of multiple pseudonyms, the irrelevance between different pseudonyms enables user data to face big data association technology, which helps to protect user sensitive information. Manufacturers can still monitor the driving data of pseudonyms. If they need to contact the vehicle immediately in an emergency, they can also obtain the contact information of the owner corresponding to the pseudonym through pseudonym resolution. Obviously, this is an effective method to take into account data utilization and privacy protection.
[0150] The related technologies proposed in this application involve vehicle-side and cloud-side, and also include regulatory technologies, which are very suitable for manufacturers who attach importance to privacy protection technology. Not only is it suitable for protecting the identity and location privacy of vehicles, but the more attractive part is the data privacy protection technology based on multiple pseudonyms, and its associated technology can reduce the concerns about user privacy leakage and data loss of control caused by big data associated technology.
[0151] In this embodiment, a first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center performs vehicle registration and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end is obtained, and the cloud-based pseudonym management system is used to activate the second-class pseudonym based on the second-class pseudonym activation request. The second-category pseudonym undergoes system authorization check and legality verification. If the system authorization check and legality verification pass, the second-category pseudonym is set to activated and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are subjected to security authentication. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first-class pseudonym to register the vehicle and generate a first-class pseudonym with a validity period that meets the preset long-term condition, and sends the first-class pseudonym to the vehicle end so that the vehicle end can generate any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second-class pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legality verification on the second-class pseudonym. If the system authorization inspection and legality verification pass, the second-class pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and superviseability. When a request for changing a second-category pseudonym is obtained, security authentication is performed on the request for changing a second-category pseudonym, the activated second-category pseudonym, and the second-category pseudonym information to be changed. If the security authentication is passed, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism is used to solve the Sybil attack problem faced by multiple pseudonyms. Vehicles can change an unlimited number of pseudonyms on demand, and save the corresponding change records to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection.
[0152] See also Figure 8As shown, the embodiment of the present invention discloses a vehicle identity management device, which may specifically include:
[0153] The pseudonym generation module 11 is used to obtain a first-class pseudonym distribution request credential through vehicle registration, and the pseudonym authentication center performs vehicle registration and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys according to the first-class pseudonym and adopts a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition;
[0154] A second-type pseudonym activation module 12, configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, perform system authorization inspection and legality verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization inspection and legality verification pass, set the second-type pseudonym as activated and generate a relevant activation certificate;
[0155] The second-category pseudonym replacement module 13 is used to perform security authentication on the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the second-category pseudonym information currently activated, when the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are obtained. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
[0156] In this embodiment, a first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center performs vehicle registration and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end is obtained, and the cloud-based pseudonym management system is used to activate the second-class pseudonym based on the second-class pseudonym activation request. The second-category pseudonym undergoes system authorization check and legality verification. If the system authorization check and legality verification pass, the second-category pseudonym is set to activated and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are subjected to security authentication. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first-class pseudonym to register the vehicle and generate a first-class pseudonym with a validity period that meets the preset long-term condition, and sends the first-class pseudonym to the vehicle end so that the vehicle end can generate any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second-class pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legality verification on the second-class pseudonym. If the system authorization inspection and legality verification pass, the second-class pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and superviseability. When a request for changing a second-category pseudonym is obtained, security authentication is performed on the request for changing a second-category pseudonym, the activated second-category pseudonym, and the second-category pseudonym information to be changed. If the security authentication is passed, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism is used to solve the Sybil attack problem faced by multiple pseudonyms. Vehicles can change an unlimited number of pseudonyms on demand, and save the corresponding change records to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection.
[0157] In some specific embodiments, the pseudonym generation module 11 may specifically include:
[0158] A vehicle registration module, used to distribute a vehicle license plate and a corresponding first-category pseudonym application certificate based on the registration request and the real registration information using a registration agency to complete vehicle registration and obtain the first-category pseudonym application request certificate for the vehicle;
[0159] The first type of pseudonym generation module is used to apply for a first type of pseudonym distribution request from a pseudonym authentication center using a first type of pseudonym application certificate, so that the pseudonym authentication center randomly generates a first type of pseudonym and a corresponding key pair based on the first type of pseudonym distribution request.
[0160] In some specific embodiments, the pseudonym generation module 11 may specifically include:
[0161] The second-category pseudonym generation module is used to send the first-category pseudonym including the request number, quantity, starting validity period, and verification certificate of the first-category pseudonym to the vehicle end, so that the vehicle end adopts a certificateless signing method according to the first-category pseudonym, utilizes a secret sharing mechanism and generates any number of second-category pseudonyms according to preset second-category pseudonym generation rules and non-association rules, utilizes the key corresponding to the first-category pseudonym as a part of the private key, and randomly generates a secret value, generates a signature key based on the part of the private key and the secret value, generates a public key for verifying the signature using the second-category pseudonym and the secret value, and generates a key corresponding to the second-category pseudonym using the signature key and the public key for verifying the signature.
[0162] In some specific embodiments, the second type of pseudonym activation module 12 may specifically include:
[0163] The authorization and legality verification module is used to use the cloud-based pseudonym management system and perform authorization authentication, pseudonym compliance verification and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
[0164] In some specific embodiments, the vehicle identity management device may further include:
[0165] A global malicious behavior supervision module is used to perform global malicious behavior supervision on all second-category pseudonyms using a pseudonym resolution system;
[0166] The parsing module is used to determine the second-class pseudonym of malicious behavior when there is a second-class pseudonym of malicious behavior, decrypt the second-class pseudonym of malicious behavior to obtain a first-class pseudonym corresponding to the second-class pseudonym of malicious behavior, parse the first-class pseudonym to obtain the real identity of the vehicle, and generate a pseudonym revocation request.
[0167] In some specific embodiments, the vehicle identity management device may further include:
[0168] The revocation module is used to determine all issued first-category pseudonyms corresponding to the real identity of the vehicle based on the pseudonym revocation request when the cloud-based pseudonym management center obtains the pseudonym revocation request, and revoke all issued first-category pseudonyms.
[0169] In some specific embodiments, the second pseudonym replacement module 13 may specifically include:
[0170] The transparent management and validity query module is used to store the second-category pseudonym activation data and the second-category pseudonym replacement data in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
[0171] Fig. 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the vehicle identity management method performed by the electronic device disclosed in any of the aforementioned embodiments.
[0172] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0173] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon include an operating system 221, a computer program 222 and data 223, etc. The storage method can be temporary storage or permanent storage.
[0174] Among them, the operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20 to realize the operation and processing of the data 223 in the memory 22 by the processor 21, which can be Windows, Unix, Linux, etc. In addition to including a computer program that can be used to complete the vehicle identity management method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks. In addition to data transmitted from an external device received by the vehicle identity management device, the data 223 can also include data collected by its own input and output interface 25, etc.
[0175] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0176] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the vehicle identity management method steps disclosed in any of the aforementioned embodiments are implemented.
[0177] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0178] The above is a detailed introduction to a vehicle identity management method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A vehicle identity management method, characterized in that: include: A first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; Obtaining a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, performing a system authorization check and a legitimacy verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization check and the legitimacy verification pass, setting the second-type pseudonym as activated, and generating a relevant activation certificate; When the second-category pseudonym replacement request sent by the vehicle, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, security authentication is performed on the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
2. The vehicle identity management method according to claim 1, characterized in that: The method of obtaining a first-class pseudonym distribution request credential through vehicle registration, and the pseudonym authentication center registering the vehicle and generating a first-class pseudonym based on the first-class pseudonym distribution request credential, comprises: Using a registration agency to distribute a vehicle license plate and a corresponding first-category pseudonym application certificate based on the registration request and the real registration information to complete vehicle registration and obtain the first-category pseudonym application request certificate for the vehicle; Use the first-class pseudonym application certificate to apply for a first-class pseudonym distribution request from the pseudonym authentication center, so that the pseudonym authentication center randomly generates a first-class pseudonym and a corresponding key pair based on the first-class pseudonym distribution request.
3. The vehicle identity management method according to claim 1, characterized in that: The sending of the first type of pseudonym to the vehicle end so that the vehicle end generates any number of second type of pseudonyms and corresponding keys according to the first type of pseudonym and using a certificateless signature method, includes: The first-category pseudonym including its request number, quantity, starting validity period, and verification credential is sent to the vehicle end, so that the vehicle end adopts a certificateless signing method according to the first-category pseudonym, utilizes a secret sharing mechanism to generate any number of second-category pseudonyms according to preset second-category pseudonym generation rules and non-association rules, utilizes the key corresponding to the first-category pseudonym as a partial private key, and randomly generates a secret value, generates a signature key based on the partial private key and the secret value, generates a public key for verifying the signature using the second-category pseudonym and the secret value, and generates a key corresponding to the second-category pseudonym using the signature key and the public key for verifying the signature.
4. The vehicle identity management method according to claim 1, characterized in that: The method of using the cloud-based pseudonym management system to perform system authorization inspection and legitimacy verification on the second type of pseudonym based on the second type of pseudonym activation request includes: The cloud-based pseudonym management system is used to perform authorization authentication, pseudonym compliance verification and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
5. The vehicle identity management method according to claim 1, characterized in that: Also includes: Use the pseudonym resolution system to conduct global malicious behavior supervision on all second-category pseudonyms; When there is a second-category pseudonym for malicious behavior, the second-category pseudonym for malicious behavior is determined, and the second-category pseudonym for malicious behavior is decrypted to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, the first-category pseudonym is parsed to obtain the true identity of the vehicle, and a pseudonym revocation request is generated.
6. The vehicle identity management method according to claim 5, characterized in that: Also includes: When the cloud-based pseudonym management center obtains the pseudonym revocation request, all issued first-category pseudonyms corresponding to the real identity of the vehicle are determined based on the pseudonym revocation request, and all issued first-category pseudonyms are revoked.
7. The vehicle identity management method according to any one of claims 1 to 6, characterized in that: The corresponding replacement record is saved to the blockchain, including: The second-category pseudonym activation data and the second-category pseudonym replacement data are stored in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
8. A vehicle identity management device, characterized in that: include: A pseudonym generation module, used to obtain a first-class pseudonym distribution request credential through vehicle registration, a pseudonym authentication center performs vehicle registration and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys according to the first-class pseudonym and adopts a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; a second-type pseudonym activation module, configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, perform system authorization inspection and legality verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization inspection and legality verification pass, set the second-type pseudonym as activated and generate a relevant activation certificate; The second-category pseudonym replacement module is used to perform security authentication on the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the second-category pseudonym information currently activated, and if the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the second-category pseudonym information currently activated is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the vehicle identity management method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program; wherein, when the computer program is executed by a processor, the vehicle identity management method as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Location privacy protection method based on dynamic pseudonym exchange area
CN109561383A
Method and system for protecting vehicle identity privacy based on certificateless authentication mechanism
CN117254915A
Conditional privacy protection authentication method based on Internet of Vehicles
CN117978537A
Message authentication method based on certificateless strong anonymity in Internet of Vehicles environment
CN118612718A