A vehicle identity management method, device, equipment and medium
By generating pseudonyms with different validity periods and using a certificateless signature method to self-issue pseudonyms, combined with a cloud-based pseudonym management system and blockchain records, the problem of massive pseudonym supply and Sybil attacks faced by multiple pseudonyms is solved, automated and transparent management of pseudonyms is achieved, and the strength of user privacy protection is improved.
Patent Information
- Application Number
- CN202510105681.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-01-23
AI Technical Summary
In existing technologies, the massive supply of pseudonyms and the Sybil attack problem faced by multiple pseudonyms lead to insufficient user privacy protection and a lack of automation and transparency in pseudonym management.
By generating first- and second-category pseudonyms with different validity periods, using a certificateless signature method to self-issue pseudonyms, combining a cloud-based pseudonym management system for system authorization and legitimacy verification, and using blockchain to record pseudonym change records, automated management and transparency of pseudonyms can be achieved.
It solves the problem of massive pseudonym supply and Sybil attacks faced by multiple pseudonyms, improves the strength of user privacy protection, realizes automated and transparent management of pseudonyms, avoids human intervention, and reduces resource waste.
Smart Images

Figure CN119945783B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a vehicle identity management method, device, equipment and medium. Background Art
[0002] Currently, in related technologies, a proxy server is set up to collect and aggregate pseudonym applications, and then the pseudonym applications are shuffled and sent to the PCA (Pseudonym Certificate Authority). The PCA cannot effectively associate the issued pseudonym with the vehicle used, thus achieving the irrelevance of the pseudonym and further improving the privacy protection strength of the vehicle. A pre-allocation strategy is adopted, in which the system pre-allocates the second type of pseudonym to be used to each vehicle, and issues it to the vehicle in one go for storage and use in sequence. To avoid Sybil attacks with multiple pseudonyms, a solution is adopted in which the validity periods of different pseudonyms do not overlap, and the pseudonym validity period is fixed, and replacement is restricted. If the pseudonym validity period is shortened (e.g., a few minutes), a vehicle will require approximately 300,000 pseudonyms per year, which is a huge number, wasteful, and costly.
[0003] As can be seen from the above, how to solve the problem of massive pseudonym supply and Sybil attacks faced by multiple pseudonyms, realize automated and transparent management of pseudonyms, and improve the strength of user privacy protection are issues to be solved in this field. Summary of the Invention
[0004] In view of this, the present invention aims to provide a vehicle identity management method, apparatus, device, and medium that can address the Sybil attack issues faced by massive pseudonyms and multiple pseudonyms, achieve automated pseudonym management, and enhance user privacy protection. The specific solution is as follows:
[0005] In a first aspect, the present application discloses a vehicle identity management method, comprising:
[0006] A first-type pseudonym distribution request credential is obtained through vehicle registration. A pseudonym authentication center registers the vehicle and generates a first-type pseudonym based on the first-type pseudonym distribution request credential, and sends the first-type pseudonym to the vehicle end, so that the vehicle end generates an arbitrary number of second-type pseudonyms and corresponding keys based on the first-type pseudonym and using a certificateless signing method; wherein the first-type pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-type pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition;
[0007] Obtaining the second type of pseudonym activation request corresponding to the second type of pseudonym sent by the vehicle end, performing system authorization verification and legality verification on the second type of pseudonym based on the cloud end pseudonym management system and the second type of pseudonym activation request, and if the system authorization verification and legality verification pass, setting the second type of pseudonym as activated, and generating relevant activation proof;
[0008] When the second type of pseudonym replacement request, the second type of pseudonym currently in use, and the second type of pseudonym information currently activated are obtained, the second type of pseudonym replacement request, the second type of pseudonym after activation, and the second type of pseudonym information to be replaced are subjected to security authentication, and if the security authentication passes, the second type of pseudonym currently in use is set to be invalid, and the second type of pseudonym information currently activated is set to be valid, and relevant valid proof is generated to complete the second type of pseudonym replacement, and the corresponding replacement record is saved to the block chain.
[0009] Optionally, the first type of pseudonym distribution request credential is obtained through vehicle registration, and the pseudonym authentication center performs vehicle registration based on the first type of pseudonym distribution request credential and generates the first type of pseudonym, comprising:
[0010] The registration authority distributes a vehicle license plate and a corresponding first type of pseudonym application credential based on the registration request and the registration real information, so as to complete vehicle registration and obtain a first type of pseudonym application request credential of the vehicle;
[0011] The first type of pseudonym application credential is used to apply for a first type of pseudonym distribution request to the pseudonym authentication center, so that the pseudonym authentication center randomly generates a first type of pseudonym and a corresponding key pair based on the first type of pseudonym distribution request.
[0012] Optionally, the first type of pseudonym is sent to the vehicle end, so that the vehicle end generates an arbitrary number of second type of pseudonyms and corresponding keys according to the first type of pseudonym and using a certificateless signature method.
[0013] The first type of pseudonym including the request number, the number, the starting validity period, and the verification credential of the first type of pseudonym is sent to the vehicle end, so that the vehicle end generates an arbitrary number of second type of pseudonyms according to the first type of pseudonym using a certificateless signature method, using a secret sharing mechanism according to a preset second type of pseudonym generation rule and a non-correlation rule, and using the key corresponding to the first type of pseudonym as a partial private key, and randomly generating a secret value, generating a signature key based on the partial private key and the secret value, generating a public key of the verification signature of the second type of pseudonym and the secret value, and generating the key corresponding to the second type of pseudonym using the signature key and the public key of the verification signature.
[0014] Optionally, the utilizing a cloud-based pseudonym management system and performing system authorization verification and legitimacy verification on the second type of pseudonym based on the second type of pseudonym activation request includes:
[0015] The cloud-based pseudonym management system is used to perform authorization authentication, pseudonym compliance verification, and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
[0016] Optionally, the vehicle identity management method further includes:
[0017] Use the pseudonym resolution system to conduct global malicious behavior supervision on all second-category pseudonyms;
[0018] When there is a second-category pseudonym for malicious behavior, the second-category pseudonym for malicious behavior is determined, and the second-category pseudonym for malicious behavior is decrypted to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, the first-category pseudonym is parsed to obtain the true identity of the vehicle, and a pseudonym revocation request is generated.
[0019] Optionally, the vehicle identity management method further includes:
[0020] When the cloud pseudonym management center obtains the pseudonym revocation request, it determines all issued first-category pseudonyms corresponding to the real identity of the vehicle based on the pseudonym revocation request and revokes all issued first-category pseudonyms.
[0021] Optionally, saving the corresponding replacement record to the blockchain includes:
[0022] The second-category pseudonym activation data and the second-category pseudonym replacement data are stored in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
[0023] In a second aspect, the present application discloses a vehicle identity management device, comprising:
[0024] A pseudonym generation module, configured to obtain a first-type pseudonym distribution request credential through vehicle registration, a pseudonym authentication center registering the vehicle and generating a first-type pseudonym based on the first-type pseudonym distribution request credential, and sending the first-type pseudonym to the vehicle end, so that the vehicle end generates an arbitrary number of second-type pseudonyms and corresponding keys based on the first-type pseudonym and using a certificateless signing method; wherein the first-type pseudonym is a vehicle pseudonym whose validity period meets a preset long-term validity condition, and the second-type pseudonym is a vehicle pseudonym whose validity period meets a preset short-term validity condition;
[0025] a second-type pseudonym activation module, configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle, perform system authorization verification and legitimacy verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization verification and legitimacy verification pass, set the second-type pseudonym as activated and generate a relevant activation certificate;
[0026] The second-type pseudonym replacement module is used to perform security authentication on the second-type pseudonym replacement request, the activated second-type pseudonym and the second-type pseudonym information to be replaced when the second-type pseudonym replacement request sent by the vehicle end, the second-type pseudonym currently in use and the currently activated second-type pseudonym information are obtained. If the security authentication passes, the second-type pseudonym currently in use is set to invalid, and the currently activated second-type pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-type pseudonym replacement and save the corresponding replacement record to the blockchain.
[0027] In a third aspect, the present application discloses an electronic device, comprising:
[0028] Memory, used to store computer programs;
[0029] The processor is used to execute the computer program to implement the aforementioned vehicle identity management method.
[0030] In a fourth aspect, the present application discloses a computer storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the vehicle identity management method disclosed above are implemented.
[0031] It can be seen that the present application provides a vehicle identity management method, including obtaining a first-class pseudonym distribution request credential through vehicle registration, a pseudonym authentication center registering the vehicle and generating a first-class pseudonym based on the first-class pseudonym distribution request credential, and sending the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; obtaining a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end, utilizing a cloud-based pseudonym management system and based on the second-class pseudonym The second-category pseudonym activation request is subjected to system authorization inspection and legitimacy verification on the second-category pseudonym. If the system authorization inspection and legitimacy verification are passed, the second-category pseudonym is set to be activated, and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle end, the currently used second-category pseudonym, and the currently activated second-category pseudonym information are obtained, a security authentication is performed on the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced. If the security authentication is passed, the currently used second-category pseudonym is set to invalid, and the currently activated second-category pseudonym information is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first type of pseudonym to register the vehicle and generate a first type of pseudonym with a validity period that meets the preset long-term validity conditions. The first type of pseudonym is sent to the vehicle end so that the vehicle end can generate any number of second type pseudonyms and corresponding keys based on the first type of pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second type of pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legitimacy verification on the second type of pseudonym. If the system authorization inspection and legitimacy verification are passed, the second type of pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and controllability. When a second-category pseudonym replacement request is obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication is passed, the second-category pseudonym currently in use will be set to invalid, and the currently activated second-category pseudonym information will be set to valid, and relevant valid certificates will be generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism solves the Sybil attack problem faced by multiple pseudonyms. Vehicles can replace an unlimited number of pseudonyms on demand, and the corresponding replacement records will be saved to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0033] Figure 1 A flow chart of a vehicle identity management method disclosed in this application;
[0034] Figure 2 A flowchart of vehicle registration and first-category pseudonym distribution disclosed in this application;
[0035] Figure 3 A flow chart of a certificateless signature scheme disclosed in this application;
[0036] Figure 4 A second type of pseudonym activation flow chart disclosed in this application;
[0037] Figure 5 A flow chart of cross-domain vehicle pseudonym management disclosed in this application;
[0038] Figure 6 A flowchart of the pseudonym-based connected car data privacy protection disclosed in this application;
[0039] Figure 7 A complete pseudonym full-cycle management flow chart disclosed in this application;
[0040] Figure 8 This is a schematic structural diagram of a vehicle identity management device disclosed in this application;
[0041] Figure 9 This is a structural diagram of an electronic device provided in this application. DETAILED DESCRIPTION
[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0043] Currently, in related technologies, a proxy server is set up to collect and aggregate pseudonym applications, and then the pseudonym applications are shuffled and sent to the PCA (Pseudonym Certificate Authority). The PCA cannot effectively associate the issued pseudonyms with the vehicles used, achieving the irrelevance of pseudonyms and further improving the strength of vehicle privacy protection. A pre-allocation strategy is adopted, in which the system pre-allocates the second type of pseudonyms to be used for each vehicle, issues them to the vehicle at one time, stores them, and uses them sequentially. To avoid Sybil attacks with multiple pseudonyms, a solution is adopted in which the validity periods of different pseudonyms do not overlap, and the pseudonym validity period is fixed, and replacement is restricted. If the pseudonym validity period is shortened (e.g., by a few minutes), a vehicle will require approximately 300,000 pseudonyms per year, which is a huge number, wasteful, and costly. As can be seen from the above, how to solve the Sybil attack problem faced by the massive supply of pseudonyms and multiple pseudonyms, realize automated and transparent management of pseudonyms, and improve the strength of user privacy protection is a problem to be solved in this field.
[0044] See also Figure 1 As shown, an embodiment of the present invention discloses a vehicle identity management method, which may specifically include:
[0045] Step S11: Obtain a first-class pseudonym distribution request credential through vehicle registration, and the pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and using a certificateless signature method; wherein, the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition.
[0046] In this embodiment, a registration authority distributes a vehicle license plate and a corresponding first-class pseudonym application certificate based on the registration request and the real registration information to complete vehicle registration and obtain the first-class pseudonym application request certificate for the vehicle; the first-class pseudonym application certificate is used to apply for a first-class pseudonym distribution request from a pseudonym authentication center, so that the pseudonym authentication center randomly generates a first-class pseudonym and a corresponding key pair based on the first-class pseudonym distribution request, and sends the first-class pseudonym including the request number, quantity, starting validity period, and verification certificate of the first-class pseudonym to the vehicle end, so that the vehicle end uses a certificateless signing method based on the first-class pseudonym, uses a secret sharing mechanism to generate an arbitrary number of second-class pseudonyms according to preset second-class pseudonym generation rules and non-association rules, and uses the key corresponding to the first-class pseudonym as a partial private key, and randomly generates a secret value, generates a signature key based on the partial private key and the secret value, generates a public key for verifying the signature using the second-class pseudonym and the secret value, and uses the signature key and the public key for verifying the signature to generate a key corresponding to the second-class pseudonym.
[0047] Among them, the process of vehicle registration and first-class pseudonym distribution is as follows Figure 2 As shown, the specific steps can be summarized as follows:
[0048] 1. A new vehicle registers its real identity with the vehicle registration agency and obtains a request certificate for a first-class pseudonym. The vehicle then uses the request certificate to request a certain number of first-class pseudonyms and corresponding keys from the first-class pseudonym distribution center.
[0049] 2. The vehicle first-class pseudonym center generates a first-class pseudonym, corresponding key, and authorization verification materials for the requesting vehicle;
[0050] 3. The vehicle's first-category pseudonym center sends the authorization verification materials corresponding to the vehicle's first-category pseudonym to the first-category pseudonym credential center for storage, so that it can be later queried and verified in the cloud;
[0051] 4. The vehicle first-class pseudonym center sends the first-class pseudonym and the corresponding key to the requesting vehicle;
[0052] 5. The vehicle generates a second type of pseudonym and corresponding signature key and verifies the signature key based on the first type of pseudonym and corresponding key;
[0053] 6. The vehicle requests the cloud-based vehicle identity management system to activate the generated second pseudonym;
[0054] 7. The cloud-based vehicle identity management system queries the first-category pseudonym storage center for authorization information of the pseudonym to be activated;
[0055] 8. After authorization is passed, the cloud-based vehicle identity management system verifies the legitimacy of the pseudonym to be activated; after passing, it confirms that the pseudonym activation is successful and the pseudonym can be put into use.
[0056] Newly connected vehicles must be registered. When registering, the real information of the vehicle and the owner is recorded. The vehicle registration agency RCA issues a license plate VID for the registered vehicle and generates n corresponding pseudonym requests for the vehicle. u,i , i = 1, 2, ..., n, and the corresponding verification credential token u,i , i=1,2,...,n,Register(VID u , req u,i , token u,i ), then (req u,i , token u,i ) is sent to the vehicle being registered.
[0057] Vehicle use (req u,i , token u,i) submits a first-class pseudonym request to the first-class pseudonym generation center, and the first-class pseudonym generation center uses (req u,i , token u,i ) to conduct security verification. After passing, for each request req u,i , i=1,2,...,n generates a first-class pseudonym and the corresponding key. The specific generation method is: the first-class pseudonym LPID_SET u ={LPID u,1 , LPID u,2 ,…,LPID u,n}, first-class pseudonym LPID u,i Indicates the valid first-class pseudonym of vehicle u in time i, and the first-class pseudonym is generated by the central registration (req u,i , LPID u,i ). Each first-class pseudonym (req u,i , LPID u,i ) corresponds to a public key and a private key (pk u,i ,sk u,i ), corresponding to a partial private key and authorization verification certificate. Then, the first-class pseudonym generation center distributes all first-class pseudonyms and corresponding key materials to the requesting vehicle.
[0058] Among them, the first type of pseudonym distribution request format (first type of pseudonym request number, quantity, starting validity period, verification certificate (cannot be reused)). Distribution information format (first type of pseudonym request number, first type of pseudonym, validity period, certificate, signature).
[0059] In this embodiment, the second-category pseudonym is generated and issued by the vehicle itself. However, the second-category pseudonym must meet certain requirements. These requirements include: the second-category pseudonym must be obtained from a valid first-category pseudonym and authorized by the system; the generated second-category pseudonym must be related to the currently valid first-category pseudonym to facilitate identity resolution when necessary. In other words, the related first-category pseudonym can be recovered from the second-category pseudonym. However, the first-category pseudonym cannot appear directly in the second-category pseudonym to ensure that the second-category pseudonym is unlinkable.
[0060] Each first-class pseudonymous LPID u,i All have a certain validity period. For the first type of pseudonym LPID within the validity period u,i , the vehicle can generate several second-class pseudonyms In order to meet the requirements of the second type of pseudonym generation, this application uses a secret sharing mechanism to generate the second type of pseudonym. The specific method is as follows:
[0061] 1. Set s=LPID u,i Shared secret, construct polynomial Where a1 is a random value. For the function value corresponding to the non-zero horizontal coordinate of the polynomial, the corresponding commitment is generated as
[0062] 2. Generate two second-class pseudonyms each time, one as a new second-class pseudonym A pseudonym as proof of identity
[0063] 3. Use Feldman VSS (a verifiable secret sharing scheme) to verify the association between the second type of pseudonym and the first type of pseudonym.
[0064] After generating the second type of pseudonym, a key corresponding to the second type of pseudonym is generated. The generated second type of pseudonym must correspond to a private key for signing and a public key for verifying the signature. Unlike the traditional public key infrastructure (PKI) digital certificate scheme, this application adopts a certificateless signature scheme. The certificateless signature scheme is a special identity-based signature scheme. Its public key does not require a digital certificate and avoids the key escrow problem. In order to generate a certificateless signature key corresponding to a short-term signature, this application proposes a message authentication using a certificateless signature scheme that can resist type I and type II attacks. The signature private key of the vehicle's second type of pseudonym consists of two parts. One part is the key corresponding to the first type of pseudonym as a partial private key in the certificateless signature scheme, and the other part is a secret value randomly generated by the vehicle module. The partial private key and the secret value generate a signature private key, and the second type of pseudonym and the secret value generate a public key for verifying the signature. The process of the certificateless signature scheme is as follows: Figure 3 As shown, the description is as follows:
[0065] Setup: Given a parameter k, KGC (Key Generation Center) generates system parameters and master keys according to the following steps: KGC generates a bilinear group (G1, G T ), where |G1| = |G T |=p, p is a prime number, and p≥2 k , k is the system security parameter. e is the bilinear mapping G1×G1→G T . Select a master key for the secure hash function. KGC Select a random element And calculate the master public key P pub =s·P, KGC announces system parameters params={G1, G T ,p,e,P,P pub , H0, H1}.
[0066] PartialPrivateKeyExtract: For a specific date vehicle select KGC for each LPID u,i , select a random number set up
[0067] SetSecretValue: User sets a short-term pseudonym Pick a random number as a secret value.
[0068] SetPrivateKey: Set the signature private key to
[0069] SetPublicKey: User ID calculation Its public key
[0070] Sign: For message m, The user calculates the signature σ = (h, W):
[0071] where the random number r∈Z p ;
[0072] (Complete the key operation of signing).
[0073] Verify: Given a user message / signature pair (m, σ=(h, W)), user public key Verify the equation Is it true? If so, the signature is correct, otherwise the signature is rejected (message, ID, signature, user public key and master public key).
[0074] Step S12: Obtain the second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, use the cloud-based pseudonym management system and perform system authorization inspection and legitimacy verification on the second-type pseudonym based on the second-type pseudonym activation request. If the system authorization inspection and legitimacy verification pass, the second-type pseudonym is set to activated and a relevant activation certificate is generated.
[0075] In this embodiment, after obtaining the second-type pseudonym activation request sent by the vehicle end, the cloud-based pseudonym management system is used to perform system authorization inspection and legality verification on the second-type pseudonym based on the second-type pseudonym activation request; the activation verification includes authorization authentication, pseudonym compliance verification and signature authentication. If the system authorization inspection and legality verification pass, the second-type pseudonym is set to activated and a relevant activation certificate is generated.
[0076] In this embodiment, the newly issued pseudonym for a vehicle must be activated by CPM (Cloud Pseudonym Management System) before it is put into use. The second type of pseudonym activation process is as follows: Figure 4As shown in Figure 1, CPM performs a complete authentication of the pseudonym to be activated. The authentication process includes pseudonym authorization authentication, pseudonym compliance check, and signature verification. For the pseudonym to be activated, authorization credentials must first be provided for authorization authentication.
[0077] The issuer of the first-class pseudonym must also construct a verifiable proof certificate for the vehicle, which proves that the vehicle's self-signed pseudonym has obtained valid system authorization. The accumulator function can give the set U, which is the set of all first-class pseudonyms, V, which is the set of used first-class pseudonyms, and x. c =LPID u,i is the pseudonym to be activated currently, W is the set of other unused first-class pseudonyms, and its authorization method is to verify x c ∈UV. The verification method adopts the password accumulator method. For the first type of pseudonym LPID u,i , its authorization token is divided into two parts (proof,token) = (acc s (W), acc x (UV)), through e(.) and group element g s It can be proved that the process uses bilinear mapping, and the specific verification method is: After passing, the vehicle can confirm (proof, token) = (acc s (W), acc x (UV)) is correct.
[0078] When activating a vehicle pseudonym, you need to provide authorization proof and present it to the Pseudonym Management Center (PMC) (LPID u,i ,proof u,i , token u,i ). PMC uses token = acc x (UV) query. If the content in the current query table is found, it means that there is no authorization. Otherwise, authorization verification is performed. If the verification fails, the authorization is not passed. No authorization or authorization verification failure will result in the second type of pseudonym being unable to be activated.
[0079] Attached to the request, g s Can be provided in advance as a public parameter or a one-time parameter, acc s (U) is used as a control to determine whether the pseudonym set is valid. Its authenticity is guaranteed by digital signature. Revoking the pseudonym set can delete the acc s (U), subsequent pseudonyms belonging to this set will no longer be activated and used. Since the vehicle revokes a used pseudonym each time, the vehicle can automatically update the authorization credentials, avoiding a large amount of credential generation and transmission overhead.
[0080] The pseudonym generation center then updates the authorization token:
[0081] The pseudonym compliance check is to confirm that the short-term pseudonym to be activated contains the first type of pseudonym verification, that is, check Whether the requirement contains a secret sharing shadow with a valid first-class pseudonym.
[0082] verify: If the verification passes, the shadow is correct.
[0083] use and Perform shared secret recovery, assuming the recovered secret is s′, verify If the verification is successful, it means that the shadow contains a valid first-class pseudonym. Then the cloud records This is to facilitate the recovery of the first-class pseudonym LPID during later pseudonym resolution. u,i .
[0084] Then, verify The correctness of the corresponding public key.
[0085] Vehicle pair The corresponding public key is self-signed, and a signature verification is required when the pseudonymous identity is activated.
[0086]
[0087] After the above steps are verified, it is proven that the pseudonym is authorized by the system, the pseudonym construction is compliant, and the pseudonym and key are consistent. The system can activate the pseudonym, record the activation of the pseudonym, and allow the activated pseudonym to enter the next stage of use or replacement.
[0088] The identity management system of this application uses a hierarchical pseudonym generation mechanism, including the vehicle's true identity (VID), a first-class pseudonym (LPID), and a second-class pseudonym (SPID). The first-class pseudonym (LPID) is used by the system to authorize the vehicle to issue its own pseudonym and serves as the key link for pseudonym resolution. The second-class pseudonym (SPID) is used to sign messages sent by the vehicle, ensuring the authenticity and tamper-proof nature of the messages. Each first-class pseudonym can have a relatively long validity period (e.g., one day), while the validity period of a second-class pseudonym can be as short as a few minutes. The VID and LPID are generated and managed by a VPKI-based credential management system. The system generates the first-class pseudonym required for a vehicle for a period of time (one or three years) using the SMCS mechanism. These pseudonyms are securely distributed to the vehicle in an encrypted and packaged manner, and the vehicle stores them in the HSM (Hardware Security Module) module in the OBU (Onboard Unit). The second-class pseudonym is generated and managed by the user through a self-agent mechanism. The second-class pseudonym must be embedded in or associated with the currently valid first-class pseudonym issued by the system. The system can derive the first-class pseudonym from the second-class pseudonym and resolve or revoke the vehicle using the first-class pseudonym. In message authentication, the vehicle signs and verifies the message using a second-class signature key. To ensure the location privacy of the vehicle, the second-class signature automatically changes keys in a timely manner based on a pseudonym change strategy.
[0089] Step S13: When the second-category pseudonym change request sent by the vehicle side, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym change request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
[0090] To prevent Sybil attacks, this application prohibits vehicles from using multiple second-category pseudonyms simultaneously. Although vehicles can generate multiple second-category pseudonyms, the pseudonyms must be activated by the system before they can be used. The system ensures that all vehicles have only one valid second-category pseudonym at a time. When a pseudonym is changed, it must undergo a series of security verifications. The newly activated pseudonym can replace the currently used pseudonym, and the replaced pseudonym will become invalid immediately. The pseudonym change operations and data are recorded in the pseudonym log server, which cannot be changed. Other users can query the validity of the pseudonym to check whether the pseudonym is valid.
[0091] The basic activation and replacement pseudonym request format is as follows:
[0092]
[0093] new After activation, determine the second type of pseudonym to be replaced Therefore, the legitimacy of the second type of pseudonym to be replaced needs to be ensured. The steps are as follows:
[0094] 1. Confirm is the current in-use pseudonym;
[0095] 2. Use and to restore the shared secret, respectively, and verify whether the first type of pseudonyms restored by the two are consistent. Consistency will ensure that the new pseudonym and the second type of pseudonym to be replaced belong to the same vehicle.
[0096]
[0097] 3. Verify the signature ability of the replaced pseudonym:
[0098]
[0099] After the check, it is proved that the vehicle possesses the signature private key of the replaced pseudonym, and indeed is the true owner of the replaced pseudonym. Thus, when the new first type of pseudonym is used for the first time to authorize a new pseudonym, the in-use pseudonym does not need to be replaced, and at other times, the new pseudonym must replace an in-use pseudonym, and the replaced pseudonym is immediately invalidated. This mechanism will ensure that the vehicle can generate several valid second type of pseudonyms, but only one of them can be enabled at the same time. Thus, the problem of multi-identity witch attack is effectively avoided.
[0100] In this embodiment, after the replacement of the second type of pseudonym is completed, the second type of pseudonym activation data and the second type of pseudonym replacement data are stored to the blockchain, so that the blockchain performs transparent management and pseudonym validity query. The blockchain data can be used as public audit support for cloud pseudonym management behavior. The system also provides validity query or proof for the current in-use second type of pseudonym of the vehicle in a whitelist manner.
[0101] The cross-domain vehicle pseudonym management process of the present application is as follows Figure 5As shown. Due to the mobility of vehicles, vehicles may travel to a different place from their jurisdiction. The pseudonyms of vehicles in different places involve cross-domain vehicle pseudonym management. In the technical solution of this application, the pseudonyms of cross-domain vehicles are still managed by the territorial vehicle management agency. Although the vehicles are located in different regions, the vehicle pseudonyms can still be generated and issued by the vehicles themselves. The activation of new pseudonyms is still managed by the jurisdiction through the network, and its processing method is consistent with the local processing method. After the new pseudonym is activated and put into use, the system will provide a validity certificate. Vehicles entering a different place can provide a validity certificate for their pseudonyms. After verification, the vehicle management agency in the different place will recognize the validity of their pseudonyms. In order to increase the security of the pseudonym system, for the pseudonyms of newly entered vehicles in different places, the pseudonym validity query can also be made to the jurisdiction of the vehicle. The territorial vehicle management agency will provide the latest information and certificate on the validity of the pseudonym. The certificate can be publicly verified and traced for audit.
[0102] Combining PKI (Public Key Infrastructure) and verifiable credential technology for vehicle digital identities enables cross-domain, remote pseudonym management. Combined with vehicle pseudonyms, channel technology is used to store vehicle data on-chain and off-chain for industrial data, ensuring privacy protection and effective utilization of vehicle data. The presence of on-chain data facilitates the authenticity of off-chain data forensics.
[0103] To ensure the transparency of pseudonym management and reduce the level of trust in CA (Certificate Authority), the system is implemented using a practical alliance chain fabric. Different organizations, including (vehicle management departments, traffic police, traffic supervision, insurance, and vehicle service providers), use blockchain technology to achieve decentralized and transparent management of vehicle identities. On-chain data is combined with off-chain data. On-chain data is used for pseudonym activation, pseudonym replacement, public audit, and pseudonym information query. Off-chain data includes key and credential information, and other non-confidential but large-scale information. To ensure system efficiency and real-time performance, a permission chain is used to provide security for on-chain data and provide external data access. Vehicles submit transaction data in the form of applications, and peers (nodes) submit transaction data. Transaction data includes pseudonym activation, replacement, query, audit, etc. The addition and modification of on-chain data are completed by smart contracts, and smart contracts are determined by relevant operating protocols.
[0104] The cryptographic accumulator used in transparent pseudonym management has two important properties: (1) for a specific element, the accumulator can have a constant membership proof size and computational cost; (2) without knowing s, the relevant credentials cannot be forged. Based on these two properties of the accumulator, the accumulator function value of the vehicle's second-class pseudonym and the corresponding public key is used as the accumulator value, and a pseudonym validity credential is constructed at the same time, which can be publicly verified. The accumulator value of the current valid pseudonym set can be stored in the blockchain, facilitating public verification by the system or other vehicles. The pseudonym validity credential is generated by the pseudonym management system and issued to the vehicle. Since pseudonyms are in a dynamic process, it is necessary to dynamically adjust the current valid pseudonym set, and at the same time adjust the accumulator value and pseudonym validity credential.
[0105] The relevant accumulator algorithm is as follows:
[0106] pp←Acc.Setup(1 λ ):System initialization, according to the system security parameter λ, generate the system public parameters, let bp = {p, G1, G2, G T ,e,g1,g2},output
[0107] A X ←Acc.Commit pp (X): Generate the accumulator value of the pseudonym set, input pseudonym set X = {x1, x2..., x n}, X(s) = Π x∈X (s+x), output
[0108] A′ X ←Acc.Add pp (A X , X, I): The accumulator value of the new set generated after the new pseudonym set is incorporated, where X←X∪I, output
[0109] A′ X ←Acc.Del pp (A X , X, I): The accumulator value of the new set after deleting the pseudonymous subset, where X←XI, output
[0110] π y ←Acc.MemProve pp (X, y): Generate membership certificate, input y∈X, output
[0111] {0, 1} ← Acc.MemVerifypp (AX, y, π y ): Membership verification, input pseudonym y∈X and qualification proof π y , if the verification is successful, output 1, otherwise output 0.
[0112] In addition, the vehicle identity management method proposed in this application also includes: using a pseudonym resolution system to perform global malicious behavior supervision on all second-category pseudonyms; when there is a second-category pseudonym for malicious behavior, determining the second-category pseudonym for malicious behavior, and decrypting the second-category pseudonym for malicious behavior to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, resolving the first-category pseudonym to obtain the true identity of the vehicle, and generating a pseudonym revocation request.
[0113] This application proposes a privacy-enhanced pseudonym resolution technology that can achieve global malicious behavior monitoring for all pseudonyms: when a pseudonym is reported to have abnormal or malicious behavior, the MA (pseudonym resolution system) performs global malicious behavior detection; after determining the malicious behavior, the corresponding first-class pseudonym LPID is derived based on the current second-class pseudonym SPID decryption, and then the pseudonym is resolved to obtain the true identity of the vehicle for accountability processing.
[0114] To prevent the real identity behind the pseudonym from being unreasonably resolved or leaked, pseudonym resolution requires sufficient justification. The resolution cannot be performed by a single department, but must be performed jointly by different departments. This application uses a privacy-enhancing method similar to the "separation of powers" for pseudonym resolution. The pseudonym resolution agency, in conjunction with the cloud management center, the first-category pseudonym generation center, and the vehicle registration agency, resolves malicious pseudonyms and obtains the corresponding vehicle's real identity (VID), thereby completing the pseudonym resolution.
[0115] Pseudonym resolution process:
[0116] Pseudonym resolution agencies and the cloud: This is to facilitate the recovery of the first-class pseudonym LPID during later pseudonym resolution. u,i ;
[0117] Pseudonym resolution agencies and first-class pseudonym generation centers: through LPID u,i Find (req u,i , LPID u,i ), and we get req u,i .
[0118] Pseudonym resolution agency and vehicle registration agency: through req u,i ,(VID u , req u,i ) Look up the table to get the real identity VID of the vehicle u .
[0119] Data is recorded during each pseudonym resolution process for later audits and privacy leak reviews.
[0120] The vehicle identity management method also includes: when the cloud pseudonym management center obtains the pseudonym revocation request, it determines all issued first-class pseudonyms corresponding to the real identity of the vehicle based on the pseudonym revocation request and revokes all issued first-class pseudonyms.
[0121] For pseudonyms with malicious behavior, pseudonym revocation must be processed after pseudonym resolution. The pseudonym revocation proposed in this application is different from the traditional revocation list-based method. It is a whitelist-based method. When a pseudonym is removed from the valid pseudonym table in the cloud, it means that the pseudonym is revoked. After the current pseudonym is revoked, the newly generated pseudonym will no longer be able to be added or replaced. Specifically, when revoking a pseudonym, all the corresponding first-class identity LPIDs that have been issued are obtained based on the real identity VID of the vehicle, and the authorization credentials corresponding to these first-class identities are revoked. For existing pseudonyms, it is no longer possible to obtain valid pseudonym credentials in use. The pseudonyms will be regarded as revoked or invalid pseudonyms and cannot be used for subsequent secure communications. These first-class identities are revoked, and the corresponding authorization credentials stored in the long-term pseudonym credential center are deleted. The vehicle will no longer be able to activate a new pseudonym, thereby completing the revocation of the vehicle pseudonym. For existing pseudonyms, it is no longer possible to obtain valid pseudonym credentials in use. The pseudonyms will be regarded as revoked or invalid pseudonyms and cannot be used for subsequent secure communications. To prevent Sybil attacks, the system prohibits vehicles from using multiple second-category pseudonyms simultaneously. Although vehicles can generate multiple second-category pseudonyms, each pseudonym must be activated by the cloud-based pseudonym management system before use. The cloud-based pseudonym management system ensures that all vehicles have only one valid second-category pseudonym at a time. Pseudonym changes are subject to a series of security verification procedures. After requesting activation from the cloud-based pseudonym management system, the new pseudonym replaces the current one, immediately invalidating the replaced one. Pseudonym changes and data are recorded in an immutable pseudonym log server. Other users can query the validity of a pseudonym to verify its validity. To ensure transparency and auditability of pseudonym operations, a blockchain is introduced to record pseudonym management operations. Pseudonym operations are automatically executed by smart contracts, and the relevant data is recorded on the blockchain. To improve system efficiency, the system records data in both on-chain and off-chain components. On-chain data is immutable and maintains the blockchain ledger, facilitating operations and data auditing. Off-chain data is controlled by on-chain data, providing efficient query and logging capabilities.
[0122] This application proposes a pseudonym-based data privacy protection technology for connected vehicles. Due to the mobility of vehicles, they may travel to locations other than their respective locations. In this case, the activation of the vehicle pseudonym is handled by the local vehicle management system, and the pseudonym management operations are also recorded in the local blockchain. In this case, the resolution of the vehicle pseudonym requires the cooperation of the local vehicle management system. Vehicle driving data is typically uploaded to the manufacturer's data center for storage to facilitate vehicle fault monitoring and accident forensics. Therefore, data authenticity and non-tampering must be addressed. In addition, since this data contains the vehicle's temporal and spatial information and contains sensitive information of many users, it is necessary to propose a comprehensive method to address these issues.
[0123] The replaceable multiple pseudonyms issued by the vehicle itself in this patent undoubtedly provide a better technical approach for data privacy protection of connected cars. Vehicle driving data relies on the pseudonym identity of the vehicle. Since different pseudonyms are uncorrelated, unlimited multiple pseudonym replacement avoids data aggregation on the data storage platform. Relevant vehicle data can still be used for vehicle status monitoring, but it is difficult to perform correlation analysis with user-sensitive spatiotemporal data. When the vehicle shows signs of failure, the manufacturer needs to contact or notify the vehicle. At this time, the pseudonym can be resolved, and the system can restore the vehicle's contact information through pseudonym resolution, which better solves the problem of data use and privacy protection. Specific solutions are as follows: Figure 6 As shown:
[0124] 1. The vehicle uploads its driving data to the vehicle manufacturer's data platform under a pseudonym;
[0125] 2. The vehicle manufacturer's data platform monitors the data and alerts the vehicle if an anomaly is found;
[0126] 3. The vehicle manufacturer's data platform sends a pseudonym resolution request to the pseudonym resolution center, requesting the contact information of the vehicle corresponding to the pseudonym;
[0127] 4. After multiple collaborations, pseudonym resolution was completed and the vehicle's contact information was obtained;
[0128] 5. The manufacturer issues vehicle condition warnings or provides corresponding services.
[0129] In summary, the complete pseudonym full-cycle management process proposed in this application is as follows: Figure 7 Shown, including:
[0130] 1. The new vehicle shall be registered with the vehicle registration agency with its real identity and obtain the first-class pseudonym certificate;
[0131] 2. The vehicle applies for a first-class pseudonym from the first-class pseudonym issuing authority, and the first-class pseudonym issuing authority distributes a first-class pseudonym set and related key materials to the vehicle;
[0132] 3. The first-class pseudonym issuing authority distributes the first-class pseudonym certificate to facilitate the pseudonym management center to verify the legal authorization of the pseudonym;
[0133] 4. The vehicle generates a short-term pseudonym and corresponding key as needed based on the valid first-class pseudonym;
[0134] 5. The vehicle requests the pseudonym management center to activate a new short-term pseudonym. After successful activation, it issues a pseudonym usage or replacement request.
[0135] 6. The Pseudonym Management Center checks and verifies the validity of pseudonyms through smart contracts;
[0136] 7. After the pseudonym validity is verified, the new pseudonym will be activated and the old pseudonym will be revoked. All operations will be recorded in the blockchain data, and relevant operations will generate verifiable credentials for subsequent use or auditing;
[0137] 8. The new pseudonym is officially enabled. Vehicles can use the new pseudonym to sign messages. Other vehicles can use the public key corresponding to the pseudonym to verify the signed message and discard messages that fail the verification.
[0138] 9. The vehicle receiving the message queries the validity of the pseudonym, which can be done online or offline;
[0139] 10. The system also has a pseudonym resolution mechanism responsible for recovering the true identity of the vehicle from the short-term pseudonym. The system can include a malicious behavior detection module to perform pseudonym identity resolution and pseudonym revocation for vehicles confirmed to have malicious behavior.
[0140] The key technologies of the entire pseudonym management system are:
[0141] 1. Controllable Vehicle Self-Issued Pseudonym Technology: Self-issued pseudonyms are supplied on demand, resolving the issue of massive pseudonym supply based on central issuance. This provides a secure mechanism for self-issuing second-category pseudonyms for vehicles, allowing vehicles to replace an unlimited number of pseudonyms on demand. The core technology addresses the compliance and controllability of pseudonyms. It introduces the concepts of first-category and second-category pseudonyms and employs certificateless signatures. First-category pseudonyms are used for system authorization, pseudonym resolution, and supervision, while second-category pseudonyms are used for secure vehicle communications. Key areas include determining the compliance and authorization of self-issued second-category pseudonyms, the legitimacy of generated pseudonyms, pseudonym activation and replacement methods, efficient pseudonym querying, and a whitelist-based pseudonym revocation mechanism.
[0142] 2. Transparent automatic pseudonym management technology: Use smart contracts to complete automated pseudonym management operations, avoiding human intervention; use an accumulator-based method to record pseudonym management operations, combined with blockchain technology to achieve public auditability of operations, effective and transparent operation and supervision.
[0143] 3. Privacy-enhanced pseudonym resolution technology: A pseudonym activation mechanism solves the Sybil attack problem faced by multiple pseudonyms; pseudonym operations are traced and related credentials are stored in the blockchain to facilitate audits and curb internal violations; a separation of powers mechanism is used for multi-party joint pseudonym resolution to enhance user privacy protection.
[0144] 4. Efficient cross-domain vehicle pseudonym query and verification technology: It can effectively manage pseudonyms of vehicles across regions and solve the problem of multiple pseudonyms being valid in different regions.
[0145] 5. Pseudonym-based connected car data privacy protection technology: Vehicle driving data is usually uploaded to the manufacturer's data center for storage, which is convenient for vehicle fault monitoring and accident evidence collection. Using the self-issued multi-pseudonym system of this application, the vehicle driving data is uploaded using the vehicle pseudonym, making the data uploaded by the vehicle anonymous. At the same time, due to the use of multiple pseudonyms, the lack of correlation between different pseudonyms makes user data able to face big data correlation technology, which helps to protect user sensitive information. Manufacturers can still monitor the driving data of pseudonyms. If they need to contact the vehicle immediately in an emergency, they can also obtain the contact information of the owner corresponding to the pseudonym through pseudonym resolution. This is an effective method that takes into account both data utilization and privacy protection.
[0146] The advantages of this application are as follows:
[0147] In terms of pseudonym supply and management: a pre-allocation scheme is adopted, and the pseudonyms are issued once for storage and use in sequence. To avoid Sybil attacks with multiple pseudonyms, a solution is adopted in which the validity periods of different pseudonyms do not overlap. The validity period of the pseudonyms is fixed and the replacement is restricted. If the validity period of the pseudonym is shortened (for example, a few minutes), a vehicle will require approximately 300,000 pseudonyms per year, which is a huge number, wasteful and costly. If the validity periods of different pseudonyms overlap, multiple pseudonyms may be valid at the same time, bringing the risk of Sybil attacks. In addition, vehicles can apply for multiple identities across domains, making it difficult to solve the problem of Sybil attacks. This application adopts a hybrid pseudonym supply method. The first type of pseudonyms are pre-allocated by the system, with a smaller number and a smaller distribution and storage burden. The second type of pseudonyms can be generated on demand, which can solve the diffusibility problem caused by massive pseudonyms. Although there have been some hybrid solutions in the past, they mainly use group signature methods. For fast-moving vehicles, group management is difficult and requires the support of the road test unit RSU, which is not ideal for practicality. The hybrid solution of this application is based on certificateless signature and adopts a set of technologies to solve the management problems of the entire life cycle, such as Sybil attacks, authorization issues, pseudonym legitimacy issues, pseudonym replacement and resolution.
[0148] Integrated application of multiple mature technologies: In view of the complexity of the full-cycle management of vehicle pseudonyms, this application comprehensively applies multiple existing technologies. In the allocation and resolution of the first type of pseudonyms, a separation of powers mechanism is adopted to enhance the system's ability to prevent privacy leakage; a certificateless signature scheme is used to implement the core technology of credential management of the second type of pseudonyms, which not only eliminates the key custody problem, but also enables the vehicle to have the ability to independently generate identity and keys; in identity construction and verification, secret sharing and password accumulators are cleverly used to complete identity authorization and compliance verification; blockchain and smart contract technologies are combined to achieve transparency and auditability of vehicle identity; the whitelist pseudonym revocation technology is used, which has high revocation efficiency compared with the traditional blacklist method.
[0149] In terms of the balance between data utilization and privacy protection of intelligent connected vehicles: Currently, the driving data of intelligent connected vehicles will be transmitted to platforms such as vehicle manufacturers. Vehicle big data can help monitor vehicle status, train and improve intelligent driving systems, provide better services, determine responsibility for vehicle accidents, and many other uses. There are problems of excessive data collection and privacy leakage. As privacy awareness and the harm of privacy leakage increase, more technologies are needed to find a balance between the two. The multi-pseudonym connected vehicle data privacy protection technology proposed in this application uses the self-issued multi-pseudonym system of this application to upload vehicle driving data using vehicle pseudonyms, making the data uploaded by the vehicle anonymized. At the same time, due to the use of multiple pseudonyms, the lack of correlation between different pseudonyms makes user data able to face big data correlation technology, which helps to protect user sensitive information. Manufacturers can still monitor the driving data of pseudonyms. If they need to contact the vehicle immediately in an emergency, they can also obtain the contact information of the owner corresponding to the pseudonym through pseudonym resolution. Obviously, this is an effective method to balance data utilization and privacy protection.
[0150] The technologies proposed in this application span both the vehicle and cloud, including regulatory technologies, making them ideal for privacy-conscious manufacturers. Beyond protecting the identity and location of vehicles, the technology's appeal lies in its multi-pseudonym-based data privacy protection. Its associated technologies can mitigate concerns about user privacy leaks and data loss caused by big data correlation.
[0151] In this embodiment, a first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end is obtained, and the cloud-based pseudonym management system is used to activate the second-class pseudonym based on the second-class pseudonym activation request. The second-category pseudonym undergoes system authorization inspection and legality verification. If the system authorization inspection and legality verification pass, the second-category pseudonym is set to activated and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first type of pseudonym to register the vehicle and generate a first type of pseudonym with a validity period that meets the preset long-term validity conditions. The first type of pseudonym is sent to the vehicle end so that the vehicle end can generate any number of second type pseudonyms and corresponding keys based on the first type of pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second type of pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legitimacy verification on the second type of pseudonym. If the system authorization inspection and legitimacy verification are passed, the second type of pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and controllability. When a second-category pseudonym replacement request is obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication is passed, the second-category pseudonym currently in use will be set to invalid, and the currently activated second-category pseudonym information will be set to valid, and relevant valid certificates will be generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism solves the Sybil attack problem faced by multiple pseudonyms. Vehicles can replace an unlimited number of pseudonyms on demand, and the corresponding replacement records will be saved to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection.
[0152] See also Figure 8As shown, the embodiment of the present application discloses a vehicle identity management device, which can specifically include:
[0153] The pseudonym generation module 11 is configured to obtain a first-type pseudonym distribution request credential through vehicle registration, and a pseudonym authentication center performs vehicle registration and generates a first-type pseudonym based on the first-type pseudonym distribution request credential, and sends the first-type pseudonym to the vehicle end, so that the vehicle end generates an arbitrary number of second-type pseudonyms and corresponding keys according to the first-type pseudonym and by using a certificateless signature method; wherein the first-type pseudonym is a vehicle pseudonym with a preset long-time validity period, and the second-type pseudonym is a vehicle pseudonym with a preset short-time validity period.
[0154] The second-type pseudonym activation module 12 is configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle end, and perform system authorization verification and legality verification on the second-type pseudonym based on the second-type pseudonym activation request by using a cloud-end pseudonym management system, and if the system authorization verification and the legality verification pass, set the second-type pseudonym as activated, and generate a relevant activation certificate.
[0155] The second-type pseudonym replacement module 13 is configured to, when obtaining a second-type pseudonym replacement request, a currently used second-type pseudonym, and a currently activated second-type pseudonym information sent by the vehicle end, perform security authentication on the second-type pseudonym replacement request, the activated second-type pseudonym, and the second-type pseudonym information to be replaced, if the security authentication passes, set the currently used second-type pseudonym as invalid, set the currently activated second-type pseudonym information as valid, and generate a relevant valid certificate, so as to complete the second-type pseudonym replacement, and save a corresponding replacement record to a block chain.
[0156] In this embodiment, a first-class pseudonym distribution request credential is obtained through vehicle registration, and a pseudonym authentication center registers the vehicle and generates a first-class pseudonym based on the first-class pseudonym distribution request credential, and sends the first-class pseudonym to the vehicle end, so that the vehicle end generates any number of second-class pseudonyms and corresponding keys based on the first-class pseudonym and a certificateless signature method; wherein the first-class pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-class pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; a second-class pseudonym activation request corresponding to the second-class pseudonym sent by the vehicle end is obtained, and the cloud-based pseudonym management system is used to activate the second-class pseudonym based on the second-class pseudonym activation request. The second-category pseudonym undergoes system authorization inspection and legality verification. If the system authorization inspection and legality verification pass, the second-category pseudonym is set to activated and a relevant activation certificate is generated; when the second-category pseudonym replacement request sent by the vehicle end, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and a relevant valid certificate is generated to complete the second-category pseudonym replacement, and the corresponding replacement record is saved to the blockchain. This application distributes request credentials based on the first type of pseudonym to register the vehicle and generate a first type of pseudonym with a validity period that meets the preset long-term validity conditions. The first type of pseudonym is sent to the vehicle end so that the vehicle end can generate any number of second type pseudonyms and corresponding keys based on the first type of pseudonym and adopt a certificateless signing method. The pseudonyms issued by the vehicle are supplied on demand to solve the problem of massive pseudonym supply and provide a safe short-term pseudonym self-issuance supply mechanism for vehicles. When the second type of pseudonym activation request is obtained, the cloud-based pseudonym management system is used to perform system authorization inspection and legitimacy verification on the second type of pseudonym. If the system authorization inspection and legitimacy verification are passed, the second type of pseudonym is set to be activated, and a relevant activation certificate is generated to solve the compliance of the pseudonym. and controllability. When a second-category pseudonym replacement request is obtained, the second-category pseudonym replacement request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced are security authenticated. If the security authentication is passed, the second-category pseudonym currently in use will be set to invalid, and the currently activated second-category pseudonym information will be set to valid, and relevant valid certificates will be generated to complete the second-category pseudonym replacement. The pseudonym activation mechanism solves the Sybil attack problem faced by multiple pseudonyms. Vehicles can replace an unlimited number of pseudonyms on demand, and the corresponding replacement records will be saved to the regional chain. Blockchain technology is used to realize decentralized vehicle multi-pseudonym management, realize transparency and automated management of pseudonym management, avoid human intervention, and improve user privacy protection.
[0157] In some specific embodiments, the pseudonym generation module 11 may specifically include:
[0158] A vehicle registration module, configured to utilize a registration authority to distribute a vehicle license plate and a corresponding first-category pseudonym application certificate based on the registration request and the real registration information, so as to complete vehicle registration and obtain the first-category pseudonym application request certificate for the vehicle;
[0159] The first type of pseudonym generation module is used to apply for a first type of pseudonym distribution request from the pseudonym authentication center using the first type of pseudonym application certificate, so that the pseudonym authentication center randomly generates a first type of pseudonym and a corresponding key pair based on the first type of pseudonym distribution request.
[0160] In some specific embodiments, the pseudonym generation module 11 may specifically include:
[0161] The second-type pseudonym generation module is used to send the first-type pseudonym including the request number, quantity, starting validity period, and verification certificate of the first-type pseudonym to the vehicle end, so that the vehicle end adopts a certificateless signing method according to the first-type pseudonym, utilizes a secret sharing mechanism to generate an arbitrary number of second-type pseudonyms according to preset second-type pseudonym generation rules and non-association rules, and utilizes the key corresponding to the first-type pseudonym as part of the private key, and randomly generates a secret value, generates a signature key based on the part of the private key and the secret value, generates a public key for verifying the signature using the second-type pseudonym and the secret value, and utilizes the signature key and the public key for verifying the signature to generate a key corresponding to the second-type pseudonym.
[0162] In some specific embodiments, the second pseudonym activation module 12 may specifically include:
[0163] The authorization and legality verification module is used to use the cloud-based pseudonym management system and perform authorization authentication, pseudonym compliance verification and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
[0164] In some specific embodiments, the vehicle identity management device may further include:
[0165] A global malicious behavior supervision module is used to perform global malicious behavior supervision on all second-category pseudonyms using the pseudonym resolution system;
[0166] The parsing module is used to determine the second-class pseudonym of malicious behavior when there is a second-class pseudonym of malicious behavior, decrypt the second-class pseudonym of malicious behavior to obtain a first-class pseudonym corresponding to the second-class pseudonym of malicious behavior, parse the first-class pseudonym to obtain the true identity of the vehicle, and generate a pseudonym revocation request.
[0167] In some specific embodiments, the vehicle identity management device may further include:
[0168] The revocation module is used to determine all issued first-class pseudonyms corresponding to the real identity of the vehicle based on the pseudonym revocation request when the cloud pseudonym management center obtains the pseudonym revocation request, and revoke all issued first-class pseudonyms.
[0169] In some specific embodiments, the second pseudonym replacement module 13 may specifically include:
[0170] The transparent management and validity query module is used to store the second-category pseudonym activation data and the second-category pseudonym replacement data in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
[0171] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the vehicle identity management method performed by the electronic device disclosed in any of the aforementioned embodiments.
[0172] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0173] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon include an operating system 221, a computer program 222 and data 223, etc. The storage method can be temporary storage or permanent storage.
[0174] The operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to realize the operation and processing of the processor 21 on the data 223 in the memory 22, and can be Windows, Unix, Linux, etc. The computer program 222 can further include a computer program capable of completing other specific work in addition to the computer program capable of completing the vehicle identity management method disclosed by the electronic device 20 executed by any one of the foregoing embodiments. The data 223 can include data transmitted by an external device received by the vehicle identity management device, data collected by the self input and output interface 25, etc.
[0175] The steps of the methods or algorithms described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0176] Further, the embodiments of the present application also disclose a computer readable storage medium, wherein the storage medium stores a computer program, and the computer program is loaded and executed by a processor to realize the steps of the vehicle identity management method disclosed by any one of the foregoing embodiments.
[0177] Finally, it should be noted that, in this document, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.
[0178] The vehicle identity management method, device, equipment and storage medium provided by the present application are described in detail above, and the principles and implementation manners of the present application are described by applying specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will be changed, and the above description of the present application should not be understood as a limitation.
Claims
1. A vehicle identity management method, characterized in that: include: A first-type pseudonym distribution request credential is obtained through vehicle registration. A pseudonym authentication center registers the vehicle and generates a first-type pseudonym based on the first-type pseudonym distribution request credential, and sends the first-type pseudonym to the vehicle end, so that the vehicle end generates an arbitrary number of second-type pseudonyms and corresponding keys based on the first-type pseudonym and using a certificateless signing method; wherein the first-type pseudonym is a vehicle pseudonym whose validity period meets a preset long-term condition, and the second-type pseudonym is a vehicle pseudonym whose validity period meets a preset short-term condition; obtaining a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle, performing a system authorization check and a legitimacy verification on the second-type pseudonym using a cloud-based pseudonym management system based on the second-type pseudonym activation request, and setting the second-type pseudonym as activated if the system authorization check and the legitimacy verification pass, and generating a relevant activation certificate; When the second-category pseudonym change request sent by the vehicle side, the second-category pseudonym currently in use, and the currently activated second-category pseudonym information are obtained, security authentication is performed on the second-category pseudonym change request, the activated second-category pseudonym, and the second-category pseudonym information to be replaced. If the security authentication passes, the second-category pseudonym currently in use is set to invalid, and the currently activated second-category pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-category pseudonym replacement, and the corresponding replacement records are saved to the blockchain.
2. The vehicle identity management method according to claim 1, characterized in that: The method of obtaining a first-class pseudonym distribution request credential through vehicle registration, and a pseudonym authentication center registering the vehicle and generating a first-class pseudonym based on the first-class pseudonym distribution request credential, includes: Using a registration authority to distribute a vehicle license plate and a corresponding first-category pseudonym application certificate based on the registration request and the real registration information to complete vehicle registration and obtain the first-category pseudonym application request certificate for the vehicle; Use the first-class pseudonym application certificate to apply for a first-class pseudonym distribution request from the pseudonym authentication center, so that the pseudonym authentication center randomly generates a first-class pseudonym and a corresponding key pair based on the first-class pseudonym distribution request.
3. The vehicle identity management method according to claim 1, characterized in that: The sending of the first type of pseudonym to the vehicle end so that the vehicle end generates any number of second type of pseudonyms and corresponding keys based on the first type of pseudonym and using a certificateless signing method includes: The first type of pseudonym including the request number, quantity, starting validity period, and verification certificate of the first type of pseudonym is sent to the vehicle end, so that the vehicle end adopts a certificateless signing method according to the first type of pseudonym, utilizes a secret sharing mechanism to generate an arbitrary number of second type pseudonyms according to the preset second type pseudonym generation rules and non-association rules, and utilizes the key corresponding to the first type of pseudonym as a partial private key, and randomly generates a secret value, generates a signature key based on the partial private key and the secret value, generates a public key for verifying the signature using the second type pseudonym and the secret value, and utilizes the signature key and the public key for verifying the signature to generate a key corresponding to the second type of pseudonym.
4. The vehicle identity management method according to claim 1, characterized in that: The method of using the cloud-based pseudonym management system and performing system authorization inspection and legitimacy verification on the second type of pseudonym based on the second type of pseudonym activation request includes: The cloud-based pseudonym management system is used to perform authorization authentication, pseudonym compliance verification, and signature authentication on the second type of pseudonym based on the second type of pseudonym activation request.
5. The vehicle identity management method according to claim 1, characterized in that: Also includes: Use the pseudonym resolution system to conduct global malicious behavior supervision on all second-category pseudonyms; When there is a second-category pseudonym for malicious behavior, the second-category pseudonym for malicious behavior is determined, and the second-category pseudonym for malicious behavior is decrypted to obtain a first-category pseudonym corresponding to the second-category pseudonym for malicious behavior, the first-category pseudonym is parsed to obtain the true identity of the vehicle, and a pseudonym revocation request is generated.
6. The vehicle identity management method according to claim 5, characterized in that: Also includes: When the cloud pseudonym management center obtains the pseudonym revocation request, it determines all issued first-category pseudonyms corresponding to the real identity of the vehicle based on the pseudonym revocation request and revokes all issued first-category pseudonyms.
7. The vehicle identity management method according to any one of claims 1 to 6, characterized in that: Saving the corresponding replacement record to the blockchain includes: The second-category pseudonym activation data and the second-category pseudonym replacement data are stored in the blockchain so that the blockchain can perform transparent management and pseudonym validity query.
8. A vehicle identity management device, characterized in that: include: A pseudonym generation module, configured to obtain a first-type pseudonym distribution request credential through vehicle registration, a pseudonym authentication center registering the vehicle and generating a first-type pseudonym based on the first-type pseudonym distribution request credential, and sending the first-type pseudonym to the vehicle end, so that the vehicle end generates an arbitrary number of second-type pseudonyms and corresponding keys based on the first-type pseudonym and using a certificateless signing method; wherein the first-type pseudonym is a vehicle pseudonym whose validity period meets a preset long-term validity condition, and the second-type pseudonym is a vehicle pseudonym whose validity period meets a preset short-term validity condition; a second-type pseudonym activation module, configured to obtain a second-type pseudonym activation request corresponding to the second-type pseudonym sent by the vehicle, perform system authorization verification and legitimacy verification on the second-type pseudonym based on the second-type pseudonym activation request using a cloud-based pseudonym management system, and if the system authorization verification and legitimacy verification pass, set the second-type pseudonym as activated and generate a relevant activation certificate; The second-type pseudonym replacement module is used to perform security authentication on the second-type pseudonym replacement request, the activated second-type pseudonym and the second-type pseudonym information to be replaced when the second-type pseudonym replacement request sent by the vehicle end, the second-type pseudonym currently in use and the currently activated second-type pseudonym information are obtained. If the security authentication passes, the second-type pseudonym currently in use is set to invalid, and the currently activated second-type pseudonym information is set to valid, and relevant valid certificates are generated to complete the second-type pseudonym replacement and save the corresponding replacement record to the blockchain.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the vehicle identity management method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the vehicle identity management method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Location privacy protection method based on dynamic pseudonym exchange area
CN109561383A
Message authentication method based on certificateless strong anonymity in Internet of Vehicles environment
CN118612718A