Authentication method, device and equipment for Internet of Vehicles

By introducing a trusted authoritative center TA into the Internet of Vehicles system for initial authentication, and using the fast re-authentication and switching authentication methods of mobile edge computing, the security challenges and low authentication efficiency in the Internet of Vehicles system are solved, and an efficient and safe vehicle authentication process is achieved.

CN119997018APending Publication Date: 2025-05-13CISDI INFORMATION TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510242759.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Because the Internet of Vehicles is highly dependent on the public network, it faces multiple security challenges such as man-in-the-middle attacks, replay attacks and impersonation attacks. In the face of frequent vehicle movement and switching, the existing authentication scheme fails to propose effective re-authentication and switching authentication methods, resulting in additional resource loss.

Method used

Provide a method for authentication of the Internet of Vehicles. Through a trusted authoritative center TA, authentication and key negotiation is carried out when the vehicle is first accessed, and then a fast re-authentication and switching authentication method based on mobile edge computing is adopted. It does not require inspection by the center server, which reduces the center authentication pressure and reduces the calculation and communication overhead of vehicle authentication.

Benefits of technology

It effectively improves the efficiency of Internet of Vehicles authentication, reduces the authentication pressure of the central server, reduces the computing and communication overhead during the vehicle authentication process, and improves the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997018A_ABST
    Figure CN119997018A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication method for the Internet of Vehicles, and the method comprises the steps: completing the authentication and key negotiation process of a vehicle and a road side unit through a trusted authority center TA under the condition that the vehicle and the road side unit are detected to be authenticated for the first time; under the condition that authentication is not carried out for the first time, the authentication of the vehicle is rapidly completed through the current road side unit, and a session key between the vehicle and the road side unit is updated; when it is detected that the authenticated vehicle moves and is switched to an unauthenticated area, data exchange and inspection between the road side unit of the current area and the road side unit authenticated last time are utilized; reliable central server auxiliary authentication is still needed when the vehicle accesses the Internet of Vehicles for the first time, then the authenticated vehicle accesses the Internet of Vehicles again, rapid re-authentication and switching authentication based on mobile edge computing are adopted, verification of the central server is not needed, the pressure of central authentication is relieved, and meanwhile the authentication efficiency is improved. The calculation and communication overhead of vehicle authentication is reduced, and the authentication efficiency is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of Internet of Vehicles, and specifically to an authentication method, device and equipment for Internet of Vehicles. Background Art

[0002] As a model of the new generation of information and communication technology, the Internet of Vehicles (IoV) has laid a solid foundation for the rapid development of intelligent transportation systems. With the continuous advancement of information and communication technology, the capabilities of IoV have been significantly improved through close cooperation and communication between vehicles and infrastructure, pedestrian systems, and cloud service providers. This improvement is not only reflected in key areas such as optimizing road networks, reducing traffic accidents, and improving transportation efficiency, but also greatly improves the experience of pedestrians and drivers, providing them with more intelligent, comfortable and convenient comprehensive services. However, due to its high reliance on public networks for information exchange, the IoV system faces multiple security challenges such as man-in-the-middle attacks, replay attacks, and impersonation attacks. Once these attacks invade the system, they may have serious consequences. During the data transmission process, sensitive data such as vehicle identity information and location coordinates are often transmitted together with the message content. If this information is illegally intercepted or leaked, it will cause a series of serious privacy leakage problems. Therefore, in the complex and changing environment of IoV, ensuring the authenticity of vehicle identity and comprehensive protection of data privacy has become a vital task. Summary of the invention

[0003] In view of the above-mentioned shortcomings of the prior art, the present application provides an authentication method, device, and equipment for a connected vehicle network, which are used to solve at least one defect in the prior art.

[0004] To achieve the above objectives and other objectives, the present application provides an authentication method for an Internet of Vehicles, the authentication method comprising:

[0005] When it is detected that the vehicle and the roadside unit are authenticated for the first time, the authentication and key negotiation process of the vehicle and the roadside unit covering the authentication area where the vehicle is located is completed through the trusted authority TA;

[0006] When it is detected that this is not the first time that the vehicle and the roadside unit are authenticated, the vehicle is authenticated through the currently authenticated roadside unit, and the session key between the vehicle and the roadside unit is updated;

[0007] When it is detected that an authenticated vehicle moves to an unauthenticated area to be authenticated, the cross-domain switching authentication of the vehicle is completed by using data exchange and verification between the roadside unit in the current area and the roadside unit that was authenticated last time, and a session key is established between the vehicle and the current roadside unit.

[0008] In one embodiment of the present application, the authentication method further includes: a trusted authority TA initializes public parameters, wherein the public parameters include {P, ΔT, h(.), q, PK TA ,Q}; Q represents the additive group whose element is P, P≠O, O represents infinity; PK TA is the public key, PK TA =s·P, s represents a random number, q represents the prime order of the point on the elliptic curve E, E:y 2 =x 3 +ax+bmodp,(a,b)∈F p , F p represents a prime finite field, p represents the size of the prime finite field, h(.):{0,1} * →{0,1} li represents the one-way collision-resistant hash function generated by the trusted authority TA, l i is the output length, and ΔT is the valid timestamp preset by the trusted authority center TA.

[0009] In one embodiment of the present application, before the vehicle and the roadside unit perform the first authentication, the method further includes: a vehicle registration step and a roadside unit registration step;

[0010] The vehicle registration steps include:

[0011] Identify ID i and password PWU i Input to vehicle V i On-board unit OBU i middle;

[0012] On-board unit OBU i Choose a random number u i As the login key, calculate the public key U i =u i P, encryption key PKU i =u i ·PK TA and false identities And {PIDU i ,U i}Sent to the trusted authority center TA;

[0013] The trusted authority center TA receives {PIDU i ,U i}, calculate the identity encryption parameter m i , and the identity encryption parameter m i Return to vehicle V i ;in, RIDU i =h(IDUi ||α TA ) is the vehicle's pseudonym, SIDU i =h(IDU i ||s) is the secret real name of the vehicle, α TA is a random number, s is a random number;

[0014] Vehicle V i Generate login key encryption parameters after receiving identity encryption parameters Encrypting parameters with login key

[0015] Generate login verification parameters Login based on the vehicle's pseudonym, vehicle's secret real name, identity, and password i =h(IDU i ||PWU i ||RIDU i ||SIDU i ) and store {α i ,β i ,Login i} to the on-board unit OBU i middle;

[0016] The roadside unit registration step comprises:

[0017] The trusted authority center TA is the roadside unit RSU j Select Real ID j , generate a random number α Rj , calculate the secret identity SIDR of the roadside unit j =h(IDR j ||s), and Sent to the roadside unit RSU j ;

[0018] Roadside Unit RSU j Received {IDR j ,SIDR j ,α Rj} and then calculate the public key of the roadside unit Then store the parameters And publish the parameters

[0019] In one embodiment of the present application, before the vehicle starts authentication, the method further includes: a vehicle login step;

[0020] User i Enter the identity token IDU i and password PWU i To On-Board Unit OBU iThen calculate the login key The vehicle's pseudonym is RIDU i With private real name SIDU i , Get login verification parameters Finally, determine the login verification parameters Login verification parameter i Are they equal? ​​If they are, the login is successful, otherwise it fails.

[0021] In one embodiment of the present application, the process of the vehicle and the roadside unit performing the first authentication includes:

[0022] Vehicle V i Choose a random number b i As the private key, calculate the public key B i =b i P. Vehicle pseudonym RIDU i , Authentication parameters Verify message And the authentication message Sent to the roadside unit RSU j ; where t i Indicates the timestamp, Indicates exclusive OR;

[0023] Roadside Unit RSU j Choose a random number b j As the private key, calculate the public key B j =b j P. Authentication parameters Verify message And the authentication message Sent to the trusted authority center TA; among them, t j Indicates a timestamp;

[0024] The trusted authority TA receives the authentication message Then calculate the vehicle's pseudonym The vehicle's secret real name is SIDU' i =h(RIDU′ i ||s), secret identity of the roadside unit SIDR′ j =h(IDR j ||s), check message Verify message Finally, check the message With verification message Are they equal? ​​If the verification message With verification message If they are equal, the authentication is successful.

[0025] In one embodiment of the present application, the authentication and key negotiation process between the vehicle and the roadside unit includes:

[0026] The trusted authority TA selects a random number b TA As the private key, and calculate the corresponding public key B TA =b TA P, calculate the pseudonym of the vehicle The private real name of the vehicle Authentication parameters Authentication parameters Verification parameters And the authentication message Sent to the roadside unit RSU j ; where t TA Indicates a timestamp;

[0027] Roadside Unit RSU j Choose a random number d j As the key negotiation private key, and calculate the corresponding key negotiation public key D j =d j P. Calculation Authentication parameters Session key encrypted value Authentication parameters Session Key Verification parameters And the authentication message Send to vehicle V i ; where t′ j Indicates a timestamp;

[0028] Vehicle V i calculate Verification parameters Session Key Verification parameters Determine the calibration parameters With verification parameters Are they equal? ​​If the verification parameters With verification parameters If they are equal, then the verification is passed, and the vehicle V i With roadside unit RSU j The session key sk is successfully negotiated between ij .

[0029] In one embodiment of the present application, when it is detected that the vehicle and the roadside unit are not authenticated for the first time, the method includes:

[0030] Vehicle V i Calculate recertification verification parameters And the authentication message Sent to the roadside unit RSU j ;

[0031] Roadside Unit RSU j Calculate the encrypted session key value Verify parameters with recertification Determine the re-authentication verification parameter R i and re-authentication verification parameter R′ i If they are equal, then verify the verification parameter R i and re-authentication verification parameter R′ i If they are equal, then the roadside unit RSU j Calculate the session key Verification parameters And the authentication message Return to vehicle V i ; Among them, T j Indicates a timestamp;

[0032] Vehicle V i Calculate a new session key Verification parameters Determine the calibration parameters Is it equal to the verification parameter? If the verification parameters With verification parameters If they are equal, the authentication of the vehicle and the roadside unit is completed.

[0033] In one embodiment of the present application, when it is detected that an authenticated vehicle moves and switches to an unauthenticated area to be authenticated, the cross-domain switching authentication of the vehicle is completed by using the data exchange and verification between the roadside unit in the current area and the roadside unit authenticated last time, and the session key between the vehicle and the current roadside unit is established, including:

[0034] Vehicle V i Calculate authentication parameters Authentication message Sent to the roadside unit RSU j+1 ;

[0035] Roadside Unit RSU j+1 Choose a random number f j As the private key, calculate the corresponding public key F j =f j P, and authenticate the message Sent to the roadside unit RSU j ;in, is the timestamp;

[0036] Roadside Unit RSU j Receive authentication message calculate Authentication parameters Determine the authentication parameter λ′ i With the authentication parameter λ i Are they equal? ​​If the authentication parameters With the authentication parameter λ i If they are equal, authentication parameters are generated. And the authentication message Return to the roadside unit RSU j+1 ; is the timestamp;

[0037] Roadside Unit RSU j+1 calculate Authentication parameters Determine the authentication parameter λ′ i With the authentication parameter λ i Are they equal? ​​If the authentication parameter λ′ i With the authentication parameter λ i If they are equal, then calculate the vehicle V i with RSU j+1 The session key encrypted value between Authentication parameters Vehicle V i with RSU j+1 The session key between Verification parameters And the authentication message Return to vehicle V i ;

[0038] Vehicle V i Receive authentication message Post-calculation Session Key Authentication parameters Determine the authentication parameter C′ j+1 Is it consistent with the authentication parameter C j+1 If the authentication parameter C′ is equal j+1 With authentication parameter C j+1 If the vehicle V i With roadside unit RSU j+1 Authentication succeeded.

[0039] To achieve the above-mentioned purpose and other related purposes, the present application provides an authentication device for a connected vehicle network, the authentication device comprising:

[0040] The first authentication module is used to complete the authentication and key negotiation process of the vehicle and the roadside unit covering the authentication area where the vehicle is located through the trusted authority center TA when it is detected that the vehicle and the roadside unit are authenticated for the first time;

[0041] A second authentication module is used to complete the authentication of the vehicle through the currently authenticated roadside unit and update the session key between the vehicle and the roadside unit when it is detected that this is not the first time for the vehicle to authenticate with the roadside unit;

[0042] The third authentication module is used to complete the cross-domain switching authentication of the vehicle by utilizing the data exchange and verification between the roadside unit in the current area and the roadside unit last authenticated when it detects that the authenticated vehicle moves and switches to an unauthenticated area to be authenticated, and at the same time establish a session key between the vehicle and the current roadside unit.

[0043] To achieve the above objectives and other related objectives, the present application provides an authentication device for an Internet of Vehicles, including:

[0044] one or more processors; and

[0045] The memory is used to store one or more programs. When the one or more programs are executed by the one or more processors, the memory implements the authentication method of the Internet of Vehicles.

[0046] To achieve the above-mentioned purpose and other related purposes, the present application provides one or more machine-readable media on which instructions are stored, which, when executed by one or more processors, enable the processors to execute the authentication method of the Internet of Vehicles.

[0047] Beneficial effects of this application:

[0048] The present application discloses an authentication method for an Internet of Vehicles, comprising: when it is detected that the authentication between a vehicle and a roadside unit is performed for the first time, the authentication and key negotiation process between the vehicle and the roadside unit is completed through a trusted authority center TA; when it is detected that the authentication between the vehicle and the roadside unit is not performed for the first time, the authentication of the vehicle is completed through the roadside unit authenticated for the last time, and the session key between the vehicle and the roadside unit is updated; the present invention fully considers that the existing authentication schemes in the Internet of Vehicles are highly dependent on the trusted authority center TA of the authority, and in the face of the need for frequent movement and switching of vehicles, only repeated execution of the initial protocol fails to propose an effective re-authentication and switching authentication method, resulting in additional resource loss. Three scenarios are proposed and corresponding authentication processes are designed respectively, namely, when a vehicle first accesses the Internet of Vehicles, a reliable central server still needs to assist in authentication, and then when an authenticated vehicle accesses the Internet of Vehicles again or switches to an unauthenticated area, a fast re-authentication and switching authentication method based on mobile edge computing is adopted, without the need for inspection by the central server, which reduces the pressure of central authentication while reducing the computing and communication overhead of vehicle authentication, and effectively improves the authentication efficiency.

[0049] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0051] Figure 1 is a schematic diagram of an implementation environment of an authentication method for a connected vehicle network shown in an exemplary embodiment of the present application;

[0052] Figure 2 A principle block diagram of a vehicle networking authentication method according to an embodiment of the present application;

[0053] Figure 3 This is a schematic diagram of an authentication device for an Internet of Vehicles according to an embodiment of the present application;

[0054] Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the memory of an embodiment of the present application is shown. DETAILED DESCRIPTION

[0055] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.

[0056] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed at will, and the component layout may also be more complicated.

[0057] Although the terms "first", "second", "A", and "B", etc. may be used herein to describe various elements, these elements should not be limited by these terms and are only used to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element without departing from the scope of the following technology. The term "and / or" includes a combination of multiple related items or any of the multiple related items.

[0058] As used herein, unless the context indicates otherwise, the singular form is intended to include the plural form, and it will be understood that the term "comprising" means the presence of stated features, quantities, steps, operations, elements, or combinations thereof, but does not exclude the presence or addition of one or more other features, quantities, steps, operations, elements, components, or combinations thereof.

[0059] Before the detailed description, it is intended to clarify that the division of components in this specification is divided only by the main function of each component. That is, two or more components to be described below can be combined into one component, or can be divided into two or more components according to more detailed functions. In addition to the main function of the component, each component to be described below can also perform some or all of the functions of other components, and some of the main functions of each component can be exclusively performed by other components.

[0060] In the process of data transmission in the Internet of Vehicles, sensitive data such as the vehicle's identity information and location coordinates are often transmitted together with the message content and illegally intercepted or leaked, causing serious privacy leakage problems. Researchers mainly focus on studying the security authentication protocol in IoV to ensure the security of vehicle communications and improve authentication efficiency. The Internet of Vehicles authentication scheme based on message authentication code (MAC) uses hard key update and soft key update strategies to effectively avoid the risk of network key leakage. It only relies on five hash functions and XOR operations between messages to achieve reliable identity authentication for Internet of Vehicles communications. However, the soft key update of this scheme depends on the original system key regularly obtained from the trusted authority (trusted authority center TA). If the trusted authority center TA is attacked and its internal information is leaked, the security of the entire IoV system will be seriously threatened. The batch authentication scheme based on elliptic curve cryptography (ECC) can efficiently process multiple signature verification requests at the same time, while the road side unit (RSU) uses a distributed topology to generate a pseudo identity and a unique signature for the vehicle. This process does not rely on a secure channel or the intervention of a trusted authority center TA, thereby simplifying the authentication process and improving efficiency. However, the RSU in this scheme is a semi-trusted entity and does not perform legitimacy authentication before vehicle communication. This vulnerability may cause sensitive information to be at risk of leakage during transmission and cannot guarantee secure communication. In order to improve the efficiency of identity authentication, a group-based authentication scheme is proposed to process multiple users at the same time. Among them, the identities of group members are systematically redefined after each group exchange process, and this method ensures the security of user privacy. Although the scheme can authenticate multiple users at the same time, the existing method based on polynomial interpolation is vulnerable to denial of service attacks, which may threaten the stability and security of the entire system. The three-factor mutual authentication and key agreement protocol based on chaotic mapping realizes a highly secure remote control function. In the identity authentication process, a physically unclonable function is introduced to generate a private key with high reliability. In addition, the protocol establishes three independent session keys between the user, the trusted authority center TA and the vehicle to ensure higher session security. The cross-domain authentication and key agreement protocol proposes a dual-signature method, which enables the edge server to efficiently authenticate two vehicles at the same time. Among them, the key agreement process only requires the transmission of only three messages, and each vehicle only needs to perform two elliptic curve point multiplication operations. The protocol not only ensures the security of communication between entities, but also reduces the computational overhead.The handover authentication scheme based on fog computing takes into account the problem that vehicles need to frequently perform legal identity authentication when moving across regions, which often leads to service response delays. In addition, each region requires vehicles to repeat the registration and identity authentication process, which increases the processing burden of the fog computing layer. A recommendation system based on vehicle-to-vehicle (V2V) communication is proposed to speed up the handover authentication process of trusted vehicles. However, fog computing nodes are usually deployed at the edge of the network and are more vulnerable to various network attacks.

[0061] In response to the above-mentioned defects, the present application provides a new authentication method for Internet of Vehicles. Figure 1 This is a schematic diagram of the implementation environment of the vehicle networking authentication method of an embodiment of the present application. In this implementation environment, it includes: the trusted authority center TA performs global parameter initialization and broadcasts it to the vehicle networking system; the vehicles and roadside units in the system register their identities with TA respectively; the vehicle needs to complete the initial verification through the login step before identity authentication; the specific authentication method is aimed at three different scenarios: when it is detected that the vehicle and the roadside unit are authenticated for the first time, the authentication and key negotiation process of the vehicle and the roadside unit is completed through the trusted authority center TA; when it is detected that the vehicle and the current roadside unit are not authenticated for the first time, the vehicle is authenticated directly through the current roadside unit and the vehicle and the roadside unit are updated. Session key; when it is detected that the authenticated vehicle moves and switches to an unauthenticated area, the cross-domain switching authentication process of the vehicle is efficiently completed by utilizing the data exchange and verification between the roadside unit in the current area and the roadside unit authenticated last time, and at the same time, a session key is established between the vehicle and the current roadside unit; the present invention still requires a reliable central server to assist in authentication when the vehicle is first connected to the Internet of Vehicles, and then when the authenticated vehicle is connected to the Internet of Vehicles again, a fast re-authentication and switching authentication method based on mobile edge computing is adopted, which does not require verification by the central server, reduces the pressure of central authentication, and reduces the computing and communication overhead of vehicle authentication, effectively improving the authentication efficiency.

[0062] The embodiments of the present application respectively propose an authentication method for an Internet of Vehicles, an authentication device for an Internet of Vehicles, and a computer-readable storage medium, and these embodiments will be described in detail below.

[0063] See also Figure 2 , Figure 2 This is a flow chart of a vehicle networking authentication method according to an embodiment of the present application. Figure 2 In the , the authentication methods of the Internet of Vehicles include:

[0064] Step S210, when it is detected that the vehicle and the roadside unit are authenticated for the first time, the authentication and key negotiation process of the vehicle and the roadside unit is completed through the trusted authority TA;

[0065] Step S220, when it is detected that this is not the first time that the vehicle and the roadside unit are authenticated, the vehicle is authenticated through the currently authenticated roadside unit, and the session key between the vehicle and the roadside unit is updated;

[0066] Step S230, when it is detected that an authenticated vehicle moves and switches to an unauthenticated area to be authenticated, the cross-domain switching authentication of the vehicle is completed by using data exchange and verification between the roadside unit in the current area and the roadside unit authenticated last time, and a session key is established between the vehicle and the current roadside unit.

[0067] Through this application, when a vehicle is connected to the Internet of Vehicles for the first time, it needs to rely on a reliable trusted authority center TA for auxiliary authentication to ensure safety; for vehicles that have passed authentication, when they are re-accessed to the Internet of Vehicles in the same area or switched to a different unauthenticated area, a fast re-authentication and switching authentication mechanism based on mobile edge computing is adopted, without the need to go through the tedious verification process of the central server again; this effectively reduces the authentication pressure of the central server, reduces the computing and communication overhead generated during the vehicle authentication process, and achieves a further improvement in authentication efficiency.

[0068] First of all, it should be noted that the authentication method of this application is an authentication method based on elliptic curve cryptography. By securely constructing an authentication public and private key pair based on elliptic curve cryptography, a vehicle login mechanism is designed to ensure the reliability of the identity of the user driving the vehicle. Specifically, only the user vehicle that has passed the login step can proceed with the subsequent authentication process. i Enter the identity token IDU i and password PWU i To On-Board Unit OBU i Then calculate the login key Vehicle pseudonyms and private real names Get login verification parameters Final judgment If yes, the login is successful, otherwise it fails.

[0069] In one embodiment, when it is detected that the vehicle and the roadside unit are authenticated for the first time, the authentication and key negotiation process of the vehicle and the roadside unit is completed through the trusted authority center TA, including: initialization of the trusted authority center TA, registration of the vehicle and the roadside unit RSU, and the first authentication and key negotiation process.

[0070] Further, the trusted authority center TA is initialized: the trusted authority center TA is responsible for the initialization of the entire system to generate various public parameters including private parameters for use by the internal system, wherein the public parameters include {P, ΔT, h(.), q, PK TA,Q}; Q represents the additive group whose element is P, P≠O, O represents infinity; PK TA is the public key, PK TA =s·P, s represents a random number, q represents the prime order of the point on the elliptic curve E, E:y 2 =x 3 +ax+bmodp,(a,b)∈F p , F p represents the prime number finite field, p represents the size of the prime number finite field, represents the one-way collision-resistant hash function generated by the trusted authority TA, l i is the output length, and ΔT is the valid timestamp preset by the trusted authority center TA.

[0071] Specifically, we first define a prime number finite field as F p , where p represents the size of the domain; in F p In the process, the trusted authority TA generates the elliptic curve E:y 2 =x 3 +ax+b mod p,(a,b)∈F p , the points on the elliptic curve E form an additive group Q with prime order q and generator P, where P≠O (O represents infinity).

[0072] Then, the trusted authority TA selects a random number s belonging to As the system master private key, calculate PK TA =s·P as the public key. After that, the trusted authority TA continues to generate a one-way collision-resistant hash function l i is the output length, and ΔT is the valid timestamp preset by the trusted authority center TA.

[0073] Finally, the trusted authority center TA announces the system public parameters {P, ΔT, h(.), q, PK TA ,Q}.

[0074] In one embodiment, the vehicle registration step includes:

[0075] User i Select a random identity ID i and password PWU i And input to the vehicle V i On-board unit OBU i Then the on-board unit OBU i Choose a random number u i As the login key, calculate the public key U i =u i P, re-encryption key PKU i =ui ·PK TA , fake identity After {PIDU i ,U i} is sent to the trusted authority center TA. After receiving the message, the trusted authority center TA first calculates Determine IDU i Is it registered in the system? If so, send a message to the vehicle V i Returns an error message, otherwise a random number α is selected TA , calculate RIDU i =h(IDU i ||α TA ),SIDU i =h(IDU i ||s) as the pseudonym and secret real name of the vehicle, and finally calculate the identity encryption parameters Then the identity encryption parameter m i Return to vehicle V i . Vehicle V i After receiving the identity encryption parameters, calculate Then generate the login key encryption parameters Encrypting parameters with login key Finally generate the login verification parameter Login i =h(IDU i ||PWU i ||RIDU i ||SIDU i ) and store {α i ,β i ,Login i} to the on-board unit OBU i middle.

[0076] The roadside unit RSU registration step includes: the trusted authority center TA is the roadside unit RSU j Select Real ID j , then generate a random number Calculating Secret Identity SIDR j =h(IDR j ||s), Sent to the roadside unit RSU j . Roadside Unit RSU j After receiving the message, calculate its public key Then store the parameters And publish the parameters

[0077] For the first authentication and key negotiation: Vehicles that have successfully logged in need to undergo authentication and key negotiation to confirm the legitimacy of their identities and to establish session keys with the roadside unit (RSU) to protect subsequent communications from being eavesdropped on and improve the security of the Internet of Vehicles. At this stage, vehicle authentication is divided into three situations, namely, first access to the Internet of Vehicles, re-access to the Internet of Vehicles in the same area, and re-access to the Internet of Vehicles after switching to a different adjacent area. The following will describe the vehicle authentication and key negotiation process in three different situations.

[0078] In one embodiment, the process of the first authentication between the vehicle and the roadside unit includes:

[0079] S1: Vehicle V i Choose a random number b i As the authentication private key, and calculate the corresponding public key B i =b i P, then generate the system current timestamp t i , calculate the authentication parameters in Represents RSU j The public key of Authentication message Send to nearby roadside unit RSU j ;in, Indicates exclusive OR;

[0080] S2: Roadside Unit RSU j Receive message authentication message M i 1 After that, first check the validity of the timestamp and judge whether |t cur -t i | is less than or equal to ΔT (where t cur is the current system time), if not, the process ends (judged as a replay attack), if yes, the timestamp verification is passed. After passing the timestamp verification, the roadside unit RSU j Choose a random number b j As its authentication private key and calculate the public key B j =b j P, records the current timestamp of the system as t j , then calculate the vehicle's pseudonym in Indicates roadside RSU j The private key of the vehicle is calculated using the pseudonym RIDU i Generate authentication parameters Finally calculate the authentication message Authentication message Sent to the trusted authority TA.

[0081] S3: The trusted authority TA receives the authentication message After that, also pass |t cur -t j | is less than or equal to ΔT, if |t cur -t j | is less than or equal to ΔT, then it is within the legal time range, and the trusted authority TA calculates the pseudonym of the vehicle The vehicle's secret real name is SIDU' i =h(RIDU′ i ||s), the secret identity of the roadside unit SIDR′ j =h(IDR j ||s), verification information Verification Information Finally, check the message With verification message If they are equal, the authentication is successful. At this time, the trusted authority TA has completed the authentication of the vehicle V i And roadside center RSU j inspection.

[0082] In one embodiment, to further support the vehicle V i With roadside center RSU j During the mutual authentication and key negotiation process, the trusted authority TA generates the current timestamp t TA , choose a random number b TA And calculate the corresponding public key B TA =b TA P, update vehicle Private real name Then calculate the authentication parameters Authentication parameters Verification Information Finally, the trusted authority center TA will authenticate the message Send to the roadside center RSU j .

[0083] Roadside Unit RSU j Receive authentication message M TA Post-verification timestamp t TA The effectiveness of the rear road side unit RSU j Choose a random number d j As the key negotiation private key, calculate the public key D j =d j P, then pass the authentication parameters calculate Using the current timestamp t′ j Calculate authentication parameters Session key encrypted value Authentication parameters Generate Session Key Finally, hash encryption is performed to generate verification parameters Authentication message Send to vehicle V i .

[0084] Vehicle V i Calculated after passing the timestamp check Verification parameters Calculate the session key Determine the calibration parameters With verification parameters Are they equal? ​​If the verification parameters With verification parameters If they are equal, then the verification is passed, and the vehicle V i With roadside unit RSU j The session key sk is successfully negotiated between ij . Since the vehicle V i Both the pseudonym and real name of the vehicle have been changed, so the vehicle V i Update login key encryption parameters Login verification parameters When you log in next time, the new parameter values ​​will be used for verification, which improves the security of login.

[0085] In one embodiment, for a re-authentication scenario within the same area, the roadside unit RSU that passed the first authentication is used to quickly complete the identity verification of the vehicle and update the session key between them.

[0086] Vehicle V i After the first successful authentication, the vehicle is disconnected from the Internet of Vehicles. When it is connected to the Internet of Vehicles again in the same area, it will be authenticated according to the re-authentication steps. When it is detected that this is not the first time that the vehicle and the roadside unit are authenticated, the method includes:

[0087] S1: Vehicle V i Record the current timestamp T i And calculate the re-authentication verification parameters Authentication message Send to RSU j .

[0088] S2: Roadside Unit RSU j Verify timestamp T i The validity of the session key is calculated after verification. Verify parameters with recertification Determine the re-authentication verification parameter Ri and re-authentication verification parameter R′ i If they are equal, the authentication is passed; if they are not equal, the authentication request is rejected. j Record the current timestamp T j , regenerate the session key and check parameters Finally, the authentication message Return to vehicle V i .

[0089] S3: Vehicle V i By using the timestamp T j After verification, a new session key is calculated Verification parameters Determine the calibration parameters Is it equal to the verification parameter? If they are equal, the authentication and key negotiation process is completed. If they are not equal, the session key is refused to be saved and the authentication fails.

[0090] For the switching authentication scenarios in different areas, the cross-domain switching authentication process of the vehicle is efficiently completed by utilizing the data exchange and verification between the current roadside unit RSU and the last authenticated roadside unit RSU, and at the same time, the session key between the vehicle and the new roadside unit RSU is established.

[0091] In one embodiment, the method further comprises: a switching authentication step for switching the authentication signal to the vehicle V i Mobile route side unit RSU j The communication range of the roadside unit RSU j+1 The communication range is completed with the road side unit RSU j+1 The handover authentication step comprises:

[0092] S1: Vehicle V i Calculate authentication parameters Then the authentication message Sent to the roadside unit RSU j+1 ;

[0093] S2: Roadside Unit RSU j+1 Verify Timestamp The legality of the j And calculate the corresponding public key F j =f j P. Record the current timestamp of the system Finally, the authentication message Sent to the roadside unit RSU j .

[0094] S3: Roadside Unit RSU j Receive authentication message Post-judgment timestamp If it is within the legal interval, the encrypted value of the session key is calculated. Determine authentication parameters Is it equal to the authentication parameter λ? i , if they are equal, generate authentication parameters Finally, the authentication message Return to the roadside unit RSU j+1 ;

[0095] S4: Roadside Unit RSU j+1 Verify Timestamp If valid, calculate Use what you get Authentication parameters Then determine the authentication parameter λ′ i With the authentication parameter λ i Are they equal? ​​If the authentication parameter λ′ i With the authentication parameter λ i If they are equal, calculate the vehicle V i With roadside unit RSU j+1 The session key encrypted value between Authentication parameters The session key is calculated as Verification parameters Authentication message Return to vehicle V i .

[0096] S5: Vehicle V i Receive authentication message You also need to check the timestamp The validity of the session key is calculated by Encrypt the value PIDU using the session key i,j+1 The session key is calculated from the value of Finally determine the authentication parameters Is it consistent with the authentication parameter C j+1 If they are equal, then the vehicle V i With roadside unit RSU j+1 The session key sk was successfully negotiated between i,j+1 .

[0097] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0098] Figure 3FIG. 1 is a block diagram of an authentication device for a connected vehicle according to an embodiment of the present application. Figure 3 As shown, an authentication device for a connected vehicle includes:

[0099] The first authentication module is used to complete the authentication and key negotiation process of the vehicle and the roadside unit covering the authentication area where the vehicle is located through the trusted authority center TA when it is detected that the vehicle and the roadside unit are authenticated for the first time;

[0100] A second authentication module is used to complete the authentication of the vehicle through the currently authenticated roadside unit and update the session key between the vehicle and the roadside unit when it is detected that this is not the first time for the vehicle to authenticate with the roadside unit;

[0101] The third authentication module is used to complete the cross-domain switching authentication of the vehicle by utilizing the data exchange and verification between the roadside unit in the current area and the roadside unit last authenticated when it detects that the authenticated vehicle moves and switches to an unauthenticated area to be authenticated, and at the same time establish a session key between the vehicle and the current roadside unit.

[0102] It should be noted that the Internet of Vehicles authentication device provided in the above embodiment and the Internet of Vehicles authentication method provided in the above embodiment belong to the same concept, wherein the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment, and will not be repeated here. In actual applications, the Internet of Vehicles authentication device provided in the above embodiment can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the device into different functional modules to complete all or part of the functions described above, and this is not limited here.

[0103] An embodiment of the present application also provides a device, including: one or more processors; and a memory for storing one or more programs, so that when the one or more programs are executed by one or more processors, the memory implements the Internet of Vehicles authentication method in the above-mentioned embodiment.

[0104] The embodiments of the present application also provide one or more machine-readable media on which instructions are stored, which, when executed by one or more processors, enable the processors to execute the Internet of Vehicles authentication method in the above-mentioned embodiments.

[0105] Figure 4 The schematic diagram of the structure of a computer system suitable for implementing the memory of the embodiment of the present application is shown. It should be noted that: Figure 4 The computer system of the memory shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0106] like Figure 4As shown, the computer system includes a central processing unit (CPU), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage part to the random access memory (RAM), such as the method in the above embodiment. In the RAM, various programs and data required for system operation are also stored. The CPU, ROM and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.

[0107] The following components are connected to the I / O interface: an input part including a keyboard, a mouse, etc.; an output part including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage part including a hard disk, etc.; and a communication part including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication part performs communication processing via a network such as the Internet. The drive is also connected to the I / O interface as needed. Removable media, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., are installed on the drive as needed so that the computer program read therefrom is installed into the storage part as needed.

[0108] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the aforementioned implementation of the vehicle network authentication method. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part, and / or installed from a removable medium. When the computer program is executed by the central processing unit (CPU), the various functions defined in the system of the present application are executed.

[0109] It should be noted that the computer-readable medium shown in the embodiment of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. This propagated data signal can take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. A computer program contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0110] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0111] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.

[0112] Another aspect of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor of a computer, the computer executes the aforementioned vehicle networking authentication method. The computer-readable storage medium may be included in the memory described in the above embodiment, or may exist independently without being assembled into the memory.

[0113] Another aspect of the present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the authentication method of the Internet of Vehicles provided in each of the above embodiments.

[0114] It should be noted that a large number of technical features are recorded in the specification of the present application, which are distributed in various technical solutions. If all possible combinations of technical features of the present application (i.e., technical solutions) are to be listed, the specification will be too long. In order to avoid this problem, the various technical features disclosed in the above-mentioned invention content of the present application, the various technical features disclosed in the various embodiments and examples below, and the various technical features disclosed in the accompanying drawings can be freely combined with each other to form various new technical solutions (these technical solutions should all be deemed to have been recorded in this specification), unless such a combination of technical features is technically infeasible. For example, in one example, feature A+B+C is disclosed, and in another example, feature A+B+D+E is disclosed, and features C and D are equivalent technical means that play the same role. Technically, only one can be used, and it is impossible to use them at the same time. Feature E can be combined with feature C technically. Then, the solution of A+B+C+D should not be deemed to have been recorded because it is technically infeasible, and the solution of A+B+C+E should be deemed to have been recorded.

[0115] The above embodiments are merely illustrative of the principles and effects of the present application, and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.

Claims

1. A vehicle networking authentication method, characterized in that: The authentication method comprises: When it is detected that the vehicle and the roadside unit are authenticated for the first time, the authentication and key negotiation process of the vehicle and the roadside unit covering the authentication area where the vehicle is located is completed through the trusted authority TA; When it is detected that this is not the first time that the vehicle and the roadside unit are authenticated, the vehicle is authenticated through the currently authenticated roadside unit, and the session key between the vehicle and the roadside unit is updated; When it is detected that an authenticated vehicle moves to an unauthenticated area to be authenticated, the cross-domain switching authentication of the vehicle is completed by using data exchange and verification between the roadside unit in the current area and the roadside unit that was authenticated last time, and a session key is established between the vehicle and the current roadside unit.

2. The vehicle networking authentication method according to claim 1, characterized in that: The authentication method also includes: a trusted authority center TA initializes public parameters, and the public parameters include {P, ΔT, h(.), q, PK TA ,Q}; Q represents the additive group whose element is P, P≠O, O represents infinity; PK TA is the public key, PK TA =s·P, s represents a random number, q represents the prime order of the point on the elliptic curve E, E:y 2 =x 3 +ax+bmodp,(a,b)∈F p , F p represents the prime number finite field, p represents the size of the prime number finite field, represents the one-way collision-resistant hash function generated by the trusted authority TA, l i is the output length, and ΔT is the valid timestamp preset by the trusted authority center TA.

3. The authentication method of the Internet of Vehicles according to claim 2, characterized in that: Before the vehicle and the roadside unit perform the first authentication, the method further includes: a vehicle registration step and a roadside unit registration step; The vehicle registration steps include: Identify ID i and password PWU i Input to vehicle V i On-board unit OBU i middle; On-board unit OBU i Choose a random number u i As the login key, calculate the public key U i =u i P, encryption key PKU i =u i ·PK TA and pseudo identity PIDU i =IDU i ⊕h(PKU i ), and {PIDU i ,U i }Send to the trusted authority center TA; The trusted authority TA receives {PIDU i ,U i }, calculate the identity encryption parameter m i , and the identity encryption parameter m i Return to vehicle V i ; Among them, m i =(RIDU i ||SIDU i )⊕h(PIDU i ||s·U i ), RIDU i =h(IDU i ||α TA ) is the vehicle's pseudonym, SIDU i =h(IDU i ||s) is the secret real name of the vehicle, IDU i =PIDU i ⊕h(s·U i ), α TA is a random number, s is a random number; Vehicle V i Generate login key encryption parameter α after receiving the identity encryption parameter i =u i ⊕h(IDU i ||PWU i ) and the login key encryption parameter β i =(RIDU i ||SIDU i )⊕h(IDU i ||PWU i ||u i ), Generate login verification parameters Login based on the vehicle's pseudonym, vehicle's secret real name, identity, and password i =h(IDU i ||PWU i ||RIDU i ||SIDU i ) and store {α i ,β i ,Login i } to the on-board unit OBU i middle; The roadside unit registration step comprises: The trusted authority center TA is the roadside unit RSU j Select Real ID j , generate a random number Calculate the secret identity of the roadside unit SIDR j =h(IDR j ||s), and Sent to the roadside unit RSU j ; Roadside Unit RSU j receive Then calculate the public key of the roadside unit Then store the parameters And publish the parameters 4. The authentication method for the Internet of Vehicles according to claim 3, characterized in that: Before the vehicle starts authentication, the method further includes: a vehicle login step; User i Enter the identity token IDU i and password PWU i To On-Board Unit OBU i Then calculate the login key u i =α i ⊕h(IDU i ||PWU i ), the vehicle's pseudonym RIDU i With private real name SIDU i , (RIDU i ||SIDU i )=β i ⊕h(IDU i ||PWU i ||u i ), get the login verification parameters Finally, determine the login verification parameters Login verification parameter i Are they equal? ​​If they are, the login is successful, otherwise it fails.

5. The authentication method for the Internet of Vehicles according to claim 4, characterized in that: The process of the vehicle and the roadside unit performing the first authentication includes: Vehicle V i Choose a random number b i As the private key, calculate the public key B i =b i ·P、Vehicle pseudonym RIDU i , authentication parameters Verify message And the authentication message Sent to the roadside unit RSU j ; where t i Represents timestamp, ⊕ represents XOR; Roadside Unit RSU j Choose a random number b j As the private key, calculate the public key B j =b j P. Authentication parameters Verify message And the authentication message Sent to the trusted authority center TA; among them, t j Indicates a timestamp; The trusted authority TA receives the authentication message Then calculate the vehicle's pseudonym The vehicle's secret real name is SIDU i '=h(RIDU i '||s), secret identity of roadside unit SIDR' j =h(IDR j ||s), check message Verify message Finally, check the message With verification message Are they equal? ​​If the verification message With verification message If they are equal, the authentication is successful.

6. The authentication method for the Internet of Vehicles according to claim 5, characterized in that: The authentication and key negotiation process between the vehicle and the roadside unit includes: The trusted authority TA selects a random number b TA As the private key, and calculate the corresponding public key B TA =b TA P, calculate the pseudonym of the vehicle The private real name of the vehicle Authentication parameters Authentication parameters Verification parameters And the authentication message Sent to the roadside unit RSU j ; where t TA Indicates a timestamp; Roadside Unit RSU j Choose a random number d j As the key negotiation private key, and calculate the corresponding key negotiation public key D j =d j P. Calculation Authentication parameters Session key encrypted value Authentication parameters Session Key Verification parameters And the authentication message Send to vehicle V i ; where t' j Indicates a timestamp; Vehicle V i calculate Verification parameters Session Key Verification parameters Determine the calibration parameters With verification parameters Are they equal? ​​If the check parameters With verification parameters If they are equal, then the verification is passed, and the vehicle V i With roadside unit RSU j The session key sk is successfully negotiated between ij .

7. The vehicle networking authentication method according to claim 6, characterized in that: When it is detected that the vehicle and the roadside unit are not authenticated for the first time, the method includes: Vehicle V i Calculate recertification verification parameters And the authentication message Sent to the roadside unit RSU j ; Roadside Unit RSU j Calculate the encrypted session key value Verify parameters with recertification Determine the re-authentication verification parameter R i and re-authentication verification parameter R' i If they are equal, then verify the verification parameter R i and recertification verification parameter R i 'Equal, then the road side unit RSU j Calculate the session key Verification parameters And the authentication message Return to vehicle V i ; Among them, T j Indicates a timestamp; Vehicle V i Calculate a new session key Verification parameters Determine the calibration parameters Is it equal to the verification parameter? If the verification parameters With verification parameters If they are equal, the authentication of the vehicle and the roadside unit is completed.

8. The vehicle networking authentication method according to claim 7, characterized in that: When it is detected that an authenticated vehicle moves and switches to an unauthenticated area to be authenticated, the cross-domain switching authentication of the vehicle is completed by using the data exchange and verification between the roadside unit in the current area and the roadside unit authenticated last time, and the session key between the vehicle and the current roadside unit is established, including: Vehicle V i Calculate authentication parameters Authentication message Sent to the roadside unit RSU j+1 ; Roadside Unit RSU j+1 Choose a random number f j As the private key, calculate the corresponding public key F j =f j P, and authenticate the message Sent to the roadside unit RSU j ;in, is the timestamp; Roadside Unit RSU j Receive authentication message calculate Authentication parameters Determine the authentication parameter λ' i With the authentication parameter λ i Are they equal? ​​If the authentication parameters With the authentication parameter λ i If they are equal, authentication parameters are generated And the authentication message Return to the roadside unit RSU j+1 ; is the timestamp; Roadside Unit RSU j+1 calculate Authentication parameters Determine the authentication parameter λ' i With the authentication parameter λ i Are they equal? ​​If the authentication parameter λ' i With the authentication parameter λ i If they are equal, then calculate the vehicle V i with RSU j+1 The session key encrypted value between Authentication parameters Vehicle V i with RSU j+1 The session key between Verification parameters And the authentication message Return to vehicle V i ; Vehicle V i Receive authentication message Post-calculation Session Key Authentication parameters Determine the authentication parameter C' j+1 Is it consistent with the authentication parameter C j+1 If the authentication parameter C' j+1 With authentication parameter C j+1 If the vehicle V i With roadside unit RSU j+1 Authentication succeeded.

9. An authentication device for a vehicle network, characterized in that: The authentication device comprises: The first authentication module is used to complete the authentication and key negotiation process of the vehicle and the roadside unit covering the authentication area where the vehicle is located through the trusted authority center TA when it is detected that the vehicle and the roadside unit are authenticated for the first time; A second authentication module is used to complete the authentication of the vehicle through the currently authenticated roadside unit and update the session key between the vehicle and the roadside unit when it is detected that this is not the first time for the vehicle to authenticate with the roadside unit; The third authentication module is used to complete the cross-domain switching authentication of the vehicle by utilizing the data exchange and verification between the roadside unit in the current area and the roadside unit last authenticated when it detects that the authenticated vehicle moves and switches to an unauthenticated area to be authenticated, and at the same time establish a session key between the vehicle and the current roadside unit.

10. An authentication device for an Internet of Vehicles, characterized in that: include: one or more processors; and A memory for storing one or more programs. When the one or more programs are executed by the one or more processors, the memory implements the Internet of Vehicles authentication method as described in any one of claims 1 to 7.

Citation Information

Cited By

  • In-band non-inductive authentication method and system for power system

    CN120263535A

  • Internet-of-vehicles road condition information transmission system based on post-quantum encryption, vehicle and medium

    CN120857107A

  • Block chain-based distributed public key distribution method and system for network-connected automatic driving Internet of Vehicles

    CN121887391A