Certificateless signature encryption method in vehicular ad hoc network communication

By using a certificate-free signature encryption method with a double-link structure and an SM9 cipher algorithm in VANETs, ​​the shortcomings of the existing technology winning password scheme in terms of storage and security are solved, and efficient and secure vehicle identity management and message transmission are achieved.

CN120034336APending Publication Date: 2025-05-23JIANGXI UNIV OF SCI & TECH

Patent Information

Application Number
CN202510170356.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing VANETs winning secret solution has problems in storage and security, high computing and communication costs, and poor security in protecting vehicle identity security and protecting malicious vehicle tracking and replay attacks.

Method used

Using a double-chain structure, combining blockchain technology and SM9 cryptographic algorithm, a certificate-free encryption method is designed. Through the public chain, the alliance blockchain stores the real identity, pseudonym and public key of the vehicle, achieving anonymity and high security. The vehicle independently calculates the complete private key to enhance the security of the private key.

Benefits of technology

It reduces the storage pressure of blockchain in VANETs, ​​improves the security and privacy of vehicle-related data, reduces communication and computing overhead, and enhances the resilience to malicious vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034336A_ABST
    Figure CN120034336A_ABST
Patent Text Reader

Abstract

The invention discloses a certificateless signcryption method in vehicle-mounted ad hoc network communication. The method comprises the following steps: a secret key generation center stores a registered user identity ID, a part of private key pairs and a public key pair in an alliance block chain; and the message sender performs signcryption on the traffic information by using a signcryption algorithm in the optimized SM9 cryptographic algorithm, generates a message tuple corresponding to the signcryption algorithm and stores the message tuple in the public block chain. And after receiving the message tuple of the sender, the message receiver verifies and decrypts the message tuple by using a decryption algorithm in the SM9 cryptographic algorithm to finally obtain a safe, complete and untampered plaintext message. According to the method, the requirements of privacy information protection and high-safety and high-efficiency vehicle-to-vehicle certificateless signcryption communication of the vehicle-mounted ad hoc network are met, potential hostile attacks are effectively resisted, the key escrow problem is solved, the calculation and communication overhead is reduced, and the safety and the traffic efficiency of the VANET are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and relates to blockchain technology in the field of information security, as well as an SM9 cryptographic algorithm and a method for proving data security. Background Art

[0002] Vehicular Ad Hoc Networks (VANETs) are self-organizing mobile ad hoc networks (MANETs) that do not require infrastructure. With the rapid development of intelligent autonomous driving and wireless communications, VANETs have important practical significance for the development of intelligent traffic systems (ITS). The messages transmitted between VANETs contain user privacy or sensitive information. Therefore, it is very important to ensure that data is transmitted confidentially, completely, securely, and anonymously in VANETs.

[0003] I. Ali et al. used an IBC-based signcryption scheme in "An efficient hybrid signcryption scheme with conditional privacy-preservation for heterogeneous vehicular communication in VANETs, IEEE Trans. Veh. Technol., vol. 69, no. 10, pp. 11266–11280, Oct. 2020". This scheme was designed for heterogeneous VANETs, capable of adapting to different types of vehicles and communication protocols, emphasizing compatibility in diverse network environments. At the same time, this scheme can also ensure the transmission of secure messages from vehicles in the IBC background to receivers in the PKI background. However, this scheme increases the implementation complexity and requires more system resources. Also, the user's private key is not derived from a confidential value, so the KGC can tamper with and forge the user's public key or use the private key for message signing. Additionally, in a high-density vehicle environment, its communication and computational overheads are still high. In the scheme proposed by Hu ishuang Shao et al. in the article "Blockchain-assisted certificateless signcryption for vehicle-to-vehicle communication in VANETs[J]. Computer Networks, 2023", users first obtain a partial private key generated by the Key Generation Center (KGC). Then, users use the partial private key and a secretly selected random value to generate a complete private key. This eliminates the key escrow storage problem and avoids the security problem of the KGC using the private key to signcrypt messages. However, there is still room for improvement in terms of signcryption and communication overheads. To reduce communication and computational overheads, Ullah et al. proposed a CLC-based online / offline homogeneous signcryption scheme in "Bilinear Pairing-Based Hybrid Signcryption for Secure Heterogeneous Vehicular Communications[J]. IEEE Transactions on Vehicular Technology, 2021". In this scheme, not many bilinear pairings are used, and by using ECC, the overheads in this scheme are reduced and the efficiency is improved. However, this scheme is not very secure in protecting vehicle identity security, malicious vehicle tracking, and replay attacks, etc., which will cause VANETs unable to operate in a highly secure environment, and the corresponding management costs will also increase.

[0004] The above schemes have improved the confidentiality and security of message dissemination to a certain extent, but most of the proposed signcryption schemes have more or less some problems in storage and security, or some of the schemes have high computational and communication costs. The characteristics of blockchain can largely ensure the security, traceability and integrity of information transmitted in VANETs. At the same time, blockchain can be used to establish a decentralized device communication platform to improve the security and interoperability of IoT devices. However, traditional solutions based on public blockchains are not suitable for real-world vehicle network scenarios, so it is necessary to deploy consortium blockchains to improve the security of vehicle networks. Solutions based on consortium blockchains provide limited access rights, high efficiency and sufficient scalability (can be expanded to a certain number of network nodes at most), while ensuring security and privacy protection. Therefore, it is crucial to propose a secure and efficient certificateless signcryption scheme. The SM9 cryptographic algorithm is an identity-based cryptographic system that can effectively solve the problems of certificate management and key escrow. The dual blockchain can ensure the secure upload and acquisition of traffic information data by trusted users in the VANETs environment, and at the same time provide good security protection for highly private information data such as vehicle public keys, real identities, pseudonyms, etc. The security proof shows that this scheme is secure against attackers who imitate ordinary users in both EUF-CMA and IND-CCA2 based on the difficulty assumption of the bilinear Diffie-Hellman problem. Summary of the invention

[0005] The purpose of the present invention is to propose a certificateless signature encryption method in vehicle-mounted self-organizing network communication. The present invention adopts a dual-chain structure. In order to reduce the storage pressure of the blockchain in VANETs, ​​on the one hand, a public chain with a low threshold is used to store traffic data, so that registered users can more easily obtain data; on the other hand, the alliance blockchain is used to store the real identity, pseudonym and public key of the vehicle, which not only reduces the storage pressure, but also improves the security of vehicle-related data. The present invention designs a certificateless signature scheme that integrates blockchain technology and SM9 cryptographic algorithm to act on V2V communication. The real identity of the vehicle generates a pseudonym through hash operation, and the pseudonym and the vehicle public key are mapped one by one on the alliance blockchain to ensure the anonymity of the vehicle in the VANETs environment and improve the security and privacy of the vehicle in the environment. In order to solve the private key management problem of KGC, the present invention obtains the complete private key through autonomous calculation after the vehicle receives the partial private key assigned by KGC, which not only increases the security of the private key, but also makes it difficult for malicious vehicles to tamper with or steal.

[0006] The certificateless signature encryption method in a vehicle-mounted self-organizing network communication described in the present invention includes a key generation center KGC, a vehicle user, a public blockchain, a consortium blockchain, and a roadside unit RSU, wherein the vehicle user is composed of a message sender and a message receiver. The message sender first encapsulates the session key using the key encapsulation algorithm in the SM9 cryptographic algorithm. After receiving the encapsulated information, the message receiver uses the partial private key assigned by the KGC and the key decapsulation algorithm of the SM9 cryptographic algorithm to perform relevant calculations to obtain the session key, so as to prepare for the subsequent message interaction between the two. During the message interaction process, the message sender first encrypts the message plaintext using the message encryption algorithm of the SM9 cryptographic algorithm and generates a corresponding message tuple and broadcasts it on the public blockchain for other vehicles to obtain. After the message receiver receives the sender's broadcast tuple, it is necessary to use the message decryption algorithm of the SM9 cryptographic algorithm to safely and accurately obtain the sender's message plaintext. If the message sender encounters a large number of messages that need to be processed and decrypted, the sender can achieve the purpose of quickly obtaining a large number of plaintext messages by executing a batch message decryption algorithm, thereby saving time and improving the communication efficiency of VANETs.

[0007] Specifically, the present invention is achieved through the following technical solutions.

[0008] The certificateless signature encryption method in a vehicle-mounted ad hoc network communication of the present invention comprises the following steps:

[0009] (S01): The key generation center KGC generates a pair of system public keys P during system initialization and vehicle identity registration. pub1 , P pub2 and the master private key 1 、s 2 , and generate two hash functions H at the same time 1 (Z,q),H 2 (Z,q); Trusted vehicle user V i You need to submit your vehicle ID to KGC i , KGC uses its ID i Generate the identifier hid with the randomly generated private key i Generate a corresponding anonymous identity PID for it i ; KGC uses the generated PID i For registered trusted vehicles V i Assign a pair of vehicle public keys Q 1,i , Q 2,i and a pair of partial private keys d 1,i d 2,i ; KGC will eventually upload the public key pair of each trusted user's vehicle to the alliance blockchain;

[0010] (S02): Vehicle V iCall the key encapsulation algorithm in the SM9 cryptographic algorithm and apply it to the vehicle V i The session key generated between the vehicle V i Using the key derivation function KDF, the random number r generated by yourself 1,i And obtain vehicle V from the alliance blockchain j The public key Q 1,i The session key K is obtained through the corresponding calculation 1,i And the session ciphertext C 1,i ; Vehicle V j After receiving the session key and ciphertext, the key decryption algorithm in the SM9 cipher is called, and the partial private key assigned by KGC and the KDF function are used to verify and calculate the session key;

[0011] (S03): Trusted Vehicle V i As the message sender, use the partial private key pair distributed by KGC and select the random number Autonomous complete private key pair {D 1,i ,D 2,i}; Vehicle V i Then two random numbers are selected to encrypt the message m by calling the message encryption algorithm, Enc encryption algorithm and message authentication code function MAC in the SM9 cryptographic algorithm. i Encryption is performed to obtain the ciphertext C i =C 2,i ||C 3,i ||C 4,i , SignatureΩ i =(S i ,h 2,i ) and key elements ω 2,i ,ω 3,i , and finally the message tuple {m i ,Ω i ,C i ,t i}Send to receiving vehicle V j , where t i is the vehicle V i Broadcast tuple {m i ,Ω i ,C i ,t i} moment.

[0012] (S04): Trusted Vehicle V j As a message receiver, it receives the message tuple {m′ i ,Ω′ i ,C′ i ,t i}, the vehicle V jFirst, check the timeliness of the message, then call the message decryption algorithm, Dec symmetric decryption algorithm and message authentication code function MAC in the SM9 cryptographic algorithm to verify the message signature. In this process, two key elements ω′ can be obtained 2,i ,ω′ 3,i And decrypt the ciphertext to obtain the secure, reliable, and untampered plaintext message m i ;

[0013] (S05): Receive vehicle V j Received from different vehicles V 1 ,V 2 ,...,V n The message tuple {m′ 1 ,Ω′ 1 ,C′ 1 ,t 1},{m′ 2 ,Ω′ 2 ,C′ 2 ,t 2},...,{m′ n ,Ω′ n ,C′ n ,t n}; Vehicle V j First check the timeliness of the message, then V j The element {ω′ 2,1 ,ω′ 3,1},{ω′ 2,2 ,ω′ 3,2},......,{ω′ 2,n ,ω′ 3,n} respectively perform aggregation processing to obtain element W 1 and W 2 ; Then vehicle V j The two elements obtained are verified, and after the verification is passed, the corresponding ciphertext decryption process is performed.

[0014] Further, in step (S01), the following steps are performed:

[0015] (1) System initialization:

[0016] The key generation center (KGC) selects three cyclic groups of order q, which are two additive cyclic groups (G 1 ,+)、(G 2 ,+), there is G 2 To G 1 Homomorphic mapping ψ, so that ψ(P 2 )=P 1 , and there is a bilinear pairing e:G 1 ×G 2 →GT ; G T is a multiplicative cyclic group; P 1 , P 2 G 1 , G 2 Generator of; cryptographic function H 1 (Z,q) and H 2 The input of (Z,q) is Z and integer q, and the output is h 1 ∈[1,q-1] and h 2 ∈[1,q-1], where q is a large prime number and Z represents a bit string;

[0017] (2) System parameter generation:

[0018] KGC randomly selects 1 ,s 2 ∈Z q * Calculate G 2 The element P in pub1 =s 1 P 2 , P pub2 =s 2 P 1 , P pub1 and P pub2 is a pair of system public keys; KGC calculates G T Element g 1 =e(P 1 ,Ppub 1 ), g 2 =e(P 2 ,Ppub 2 ), then set the parameters params = {q,P 1 ,P 2 ,Ppub 1 ,Ppub 2 ,g 1 ,g 2 ,H 1 ,H 2 ,G 1 ,G 2 ,G T}Publicly expose the parameters on the VANET and send s 1 ,s 2 Secret storage;

[0019] (3) Vehicle information generation:

[0020] KGC randomly generates a large byte HID i Represents a trusted vehicle V i Private key generates identifier and calculates PID i =h1,i , where h 1,i =H(ID i ||hid i ,q),PID i Give the vehicle V for KGC i Generated anonymous identity; KGC calculates t 1,i =h 1,i +s 1 , t′ 1,i =h 1,i +s 2 If t 1,i ,t′ 1,i ≠0, then calculate t 2,i =s 1 / t 1,i , t′ 2,i =s 2 / t 2,i , then calculate:

[0021]

[0022] d 1,i , d 2,i As a vehicle V i Partial private key pair;

[0023]

[0024] Q 1,i ,Q 2,i As a vehicle V i Public key pair; finally KGC sends a public key pair to the trusted vehicle V i Send key i ={d 1,i ,d 2,i ,Q 1,i ,Q 2,i ,PID i};

[0025] The key encapsulation and decapsulation algorithm based on the SM9 cryptographic algorithm described in step (S02) of the present invention includes the following specific contents:

[0026] (1) Session key encapsulation

[0027] V i Generate a random number r 1,i ∈Z q * , and calculate G 1 The element C 1,i =r 1,i Q 1,j , and then C 1,i The data type of V is converted to a bit string; i Calculate GT Elements in And ω 1,i Convert data type to bit string; calculate K 1,i =KDF(C 1,i ||ω 1,i ||ID i ,klen 1 ), if K 1,i If it is a string of all zero bits, return to (1) to regenerate the random number r 1,i Calculate; otherwise V i Output (K 1 ,i,C 1 ,i), where K 1 ,iThe encapsulated key, C 1 ,i is KGC and vehicle V i The corresponding ciphertext generated by the session; finally V i (K 1,i ,C 1,i ) is sent to the corresponding vehicle V j ;

[0028] (2) Session key decryption

[0029] Vehicle V j Received (K 1,i ,C 1,i ) and then verify the ciphertext C 1,i ∈G 1 Is it true? If not, exit and report to KGC; if true, then vehicle V j Calculate G T The element ω′ in 1,i =e(C 1,i ,d 1,j ), and at the same time 1,i The data type is converted into a bit string; the received C 1,i Convert the data type to a bit string and calculate V i Encapsulated key K′ 1,i =KDF(C 1,i ||ω′ 1,i ||ID i ,klen 1 ), KDF is a key derivation function, if K′ 1,i All 0 or K 1,i =K′ 1,i If it is not established, then an error will be reported and the vehicle will exit; otherwise, the vehicle V i Securely accept the session key K 1,i .

[0030] The message encryption algorithm based on the SM9 cryptographic algorithm described in step (S03) of the present invention includes the following specific contents:

[0031] (1) Private key generation

[0032] Vehicle V i Select random number V i calculate

[0033]

[0034] D 1,i ,D 2,i As a vehicle private key pair;

[0035] (2) Message Signcryption

[0036] 1) Vehicle V i Choose a random number r 2,i , Calculate G 1 and G T The element C in 3,i =r 3,i Q 1,j ,

[0037] 2) Calculate h 2,i =H 2 (m i ||ω 2,i ,q),L i =(r 2,i -h 2,i )modq; if L i = 0, then return to (1) and reselect the random number r 2,i ; Otherwise calculate K 2,i =KDF(C 2,i ||ω 3,i ||ID j ,klen)=K 1 _len||K 2 _len, input klen represents the length of the secret key;

[0038] 3) Calculate S i =L i ·D 1,i , let Ω i =(S i ,h 2,i ), calculate C 4,i =Enc(K 1 _len,m i ), Enc is a symmetric encryption algorithm; calculate C 5,i =MAC(K 2 _len,C 4,i), MAC is a message authentication function, the purpose is to prevent the input data from being maliciously tampered with;

[0039] 4) Finally output the ciphertext C i =C 3,i ||C 4,i ||C 5,i ; and {m i ,Ω i ,C i ,t i}Send to other vehicles V j , where t i is the vehicle V i Broadcast tuple {m i ,Ω i ,C i ,t i}; at the same time, the broadcast tuple will also be stored on the public chain for other trusted vehicles to obtain.

[0040] The message decryption algorithm based on the SM9 cryptographic algorithm described in step (S04) of the present invention includes the following specific contents:

[0041] (1) Check the transmission delay

[0042] Vehicle V j Accept the message tuple {m′ i ,Ω′ i ,C′ i ,t i}Vehicle based on arrival time t j and the previous moment t i To check the transmission delay; first the vehicle V j Judgement j -t i > Δt is true, if true, directly refuse to accept the message tuple, otherwise the message recipient V j Execute the following steps, where Δt is the specified maximum transmission delay;

[0043] (2) Message decryption

[0044] 1) Vehicle V j Verify h′ 2,i ∈Z q * , S′ i ∈G 1 Is it true? If not, the verification fails. Otherwise, from C′ i Take out C′ 2,i , verify C′ 2,i ∈G 1 Is it established? If not, report to KGC. Otherwise:

[0045] Calculate G T Mediumω′ 3,i =e(C′ 2,i ,D 2,i ), u i =e(S′ i ,Q 2,i );

[0046] 2) Calculate K′ 2,i =KDF(C′ 2,i ||ω′ 3,i ||ID j ,klen)=K′ 1 _len||K′ 2 _len,ω′ 2,i =u i ·t i ;

[0047] 3) Calculate h′ 2,i =H 2 (m′ i ||ω′ 2,i ,q), check h 2,i =h′ 2,i Is it true? If not, report an error and report to KGC. Otherwise, calculate m′ i = Dec(K′ 1 _len,C′ 3,i ), Dec is a symmetric decryption algorithm;

[0048] 4) Calculate f i =MAC(K′ 2 _len,C′ 3,i ), from C′ i Take out C′ 3,i , judge f i =C′ 4,i If not, exit and report to KGC, otherwise output message m' i .

[0049] The message decryption algorithm based on the SM9 cryptographic algorithm described in step (S05) of the present invention includes the following specific contents:

[0050] (1) Check the transmission delay

[0051] When receiving vehicle V j Received from different vehicles V 1 ,V 2 ,...,V n The message tuple {m′ 1 ,Ω′ 1 ,C′ 1,t 1},{m′ 2 ,Ω′ 2 ,C′ 2 ,t 2},...,{m′ n ,Ω′ n ,C′ n ,t n}; The vehicle first checks the timeliness of the message. If it exceeds the specified maximum transmission delay, the message is rejected. Otherwise, the receiver starts to recover the message. Vehicle V j Accept each message array {m′ i ,Ω′ i ,C′ i ,t i};

[0052] (2) Batch message decryption

[0053] 1) Vehicle V j Verify that {Ω 1 ,......Ω n} The elements in S′ 1 ,......S′ n ∈G 1 Is it true? If not, the verification fails. Otherwise, from each received tuple C′ i Take out C′ 2,i , verify C′ 2,i ∈G 1 Is it established? If not, report to KGC. Otherwise:

[0054] Calculate G T Mediumω′ 3,i =e(C 2,i ,D 2,i ),

[0055] 2) Verification Is it true? If not, the message recovery fails. Otherwise:

[0056] 3) Calculate K′ for each message tuple separately 2,i =KDF(C′ 2,i ||ω′ 3,i ||ID j ,klen)=K′ 1 _len||K′ 2 _len;

[0057] 4) Calculate m′ separately i = Dec(K′ 1 _len,C′3,i ), restore the plaintext message, Dec is the symmetric decryption algorithm;

[0058] 5) Calculate f separately i =MAC(K′ 2 _len,C′ 3,i ), from each tuple containing C′ i Take out C′ 4,i , judge f i =C′ 4,i Is it true? If not, exit and report to KGC, otherwise output the message {m′ 1 ,......,m′ n}. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 This is a system model diagram of the information security sharing solution without certificate signature encryption of the present invention.

[0060] Figure 2 Algorithm flow chart of the information security sharing scheme without certificate signature encryption of the present invention

[0061] Figure 3 This is an information interaction diagram of the information security sharing scheme of the certificateless signature encryption of the present invention.

[0062] Figure 4 This is the signcryption calculation overhead diagram of the information security sharing scheme of certificateless signature encryption of the present invention.

[0063] Figure 5 This is a comparison chart of the decryption computation overhead of the information security sharing scheme of the certificateless signature encryption of the present invention.

[0064] Figure 6 This is a comparison chart of the batch decryption computational overhead of the information security sharing scheme of the certificateless signature encryption of the present invention. DETAILED DESCRIPTION

[0065] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.

[0066] 1. The model structure layout of the present invention.

[0067] like Figure 1 For the overall structure of the present invention, the specific parameters are defined as follows:

[0068] Vehicles: Each intelligent vehicle is equipped with a wireless-enabled On-Board Unit (OBU). The OBU obtains the vehicle's dynamic information from Road Side Units (RSUs) or other vehicles and shares traffic-related messages through DSRC technology or the PC5 interface between Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communications. To avoid privacy leakage, each vehicle uses an anonymous identity issued by the Key Generation Center (KGC) for communication. In addition, each OBU is synchronized with the system time of all entities in the Vehicular Ad Hoc Networks (VANETs).

[0069] Key Generation Center (Trusted Authority, TA): The KGC has powerful computing capabilities and storage space in VANETs, is not easily vulnerable to malicious attacks, and is fully trusted. It is responsible for the system initialization and generates a series of public parameters to assist roadside units and users in completing registration.

[0070] Road Side Unit (RSU): The roadside unit nodes are used to provide communication and interaction between vehicles and infrastructure. Through wireless communication technologies such as vehicle-mounted communication, Wi-Fi, cellular networks, etc., they communicate bidirectionally with vehicles. Specifically, the RSU can collect data generated by roadside vehicle sensors, traffic lights, cameras and other devices, and transmit this data to the cloud or other central locations for use in traffic management, intelligent transportation systems, etc. At the same time, through its location beside the road, it increases the coverage of vehicle communication, improves the reliability and continuity of communication, and thus completes user identity authentication, task data processing, and consensus. It has powerful computing and storage capabilities and, as a management node in the blockchain, can view vehicle messages in real time and record them in the blockchain.

[0071] Users: Users include the Message Sender (MS) and the Message Receiver (MR), and the specific definitions are as follows:

[0072] (1) Message Sender (MS): They are usually ordinary vehicle users who provide information such as roads. When an MS encounters a traffic accident or other road traffic events, the vehicle user obtains the message tuple corresponding to the message through the message signcryption algorithm and broadcasts it on the public blockchain for other MRs to obtain in a timely manner, so as to quickly understand the relevant road information, and ultimately increase the traffic efficiency in the VANETs environment.

[0073] (2) Message Receiver (MR): They are usually vehicle users who need to obtain road messages in a timely manner. Without knowing the current road information, the MR quickly obtains the message tuple published by the MS on the public blockchain and uses the message decryption algorithm to obtain the road information safely, accurately, and completely.

[0074] Public blockchain: The entry threshold of the public blockchain is low. The system can read data and send confirmation transactions by default. It protects user rights from the influence of program developers through token encouragement and competitive accounting. As a decentralized distributed ledger technology, it stores data in the form of blocks and uses cryptographic methods to ensure the security and immutability of data. The present invention uses these characteristics to encrypt user privacy information and save it in the blockchain to ensure the validity and integrity of user identity, while storing transaction information in the blockchain to ensure the fairness of transactions. . This solution uses the public chain to store road and traffic information, which is convenient for registered trusted users to obtain the traffic information they want in a timely manner from the public chain stored in the OBU.

[0075] Alliance blockchain: Each organization in the alliance blockchain has one or more nodes. Data is only allowed to be read, written and sent by different organizations in the system, and the permissions of participating nodes are completely equal. This solution uses the alliance blockchain to store the real and anonymous identities of each pair of registered vehicles and the vehicle public key. Only with the permission of a trusted organization can personal privacy information be obtained. The alliance blockchain provides vehicle public key query services for registered vehicles based on the one-to-one mapping between anonymous identities and vehicle public keys.

[0076] SM9 cryptographic algorithm: The National Secret SM9 cryptographic algorithm is an identity-based public key cryptographic algorithm (Identity-Based Encryption, IBE). The main feature of the SM9 algorithm is that it directly generates public keys based on the user's identity information (such as username or email address), without the need for complex certificate management and public key distribution processes, thereby simplifying the management of the public key infrastructure (PKI). The National Secret SM9 identity cryptographic algorithm consists of four parts: signature verification algorithm, key encapsulation and decapsulation algorithm, encryption and decryption algorithm, and key exchange algorithm. The National Secret SM9 cryptographic algorithm has become an important public key cryptographic algorithm with its unique identity-based key management mechanism, efficient algorithm performance, wide application scenarios, and strict security assumptions. It not only simplifies the key management process, but also provides efficient security protection, suitable for a variety of modern application needs.

[0077] 2. The information security sharing scheme of the present invention without certificate signature encryption

[0078] The process of the certificateless signature encryption scheme integrating dual blockchain and SM9 cryptographic algorithm in VANET communication proposed by the present invention is as follows: Figure 2 shown.

[0079] (1) Setup: During the system initialization phase, after inputting the security parameter k, KGC generates the system master private key and publishes the system security parameters, where k is a positive integer.

[0080] (2) RegAIDPSK: KGC uses the real identity ID of the trusted user to generate a corresponding pseudonym, partial private key and public key for it, and stores the above data securely in the alliance chain.

[0081] (3) Session key encapsulation for vehicles: Vehicle users use their own vehicle public key and real identity ID to generate a separate session key and encrypt it, and then send the encapsulated ciphertext to the corresponding vehicle user.

[0082] (4)Session key unblocking for vehicles: The vehicle user receives the encapsulated ciphertext sent by other users and verifies and unblocks it.

[0083] (5) SPKGen: The trusted vehicle uses the partial private key and public key distributed by KGC and the system security parameters to autonomously generate a complete private key.

[0084] (6) Sighcrypt: The message sender uses its own complete private key, public key, pseudonym, etc. as the algorithm to complete the signcryption of the message plaintext and obtain the message ciphertext. The pseudonym and public key can be quickly obtained from the alliance blockchain.

[0085] (7) Unsighcrypt: The message receiver uses the received message tuple, the vehicle public key, its own pseudonym and real identity to decrypt the ciphertext and obtain the plaintext of the message.

[0086] The data interaction process in the certificateless signature encryption scheme is as follows: Figure 3 shown.

[0087] Vehicle V i , V j First, provide the real identity ID to KGC, and then KGC uses the secret key generation algorithm to obtain V i , V j Their respective pseudonyms, partial private keys, and vehicle public key Q 1,i Q 2,i Q 1,j Q 1,j , and then KGC stores all the above information in the alliance blockchain. i Need to send a message to the target vehicle V j When the target vehicle V is obtained from the alliance blockchain, j The vehicle public key is combined with its own private key to encrypt the message using the SM9 message encryption algorithm and generate the corresponding message tuple {m i ,Ω i ,C i ,t i} where Ω is the message signature, C i is the message ciphertext. Vehicle V i It is stored on the alliance blockchain to facilitate other vehicles to obtain the message. j Received message tuple {m′ i ,Ω′ i ,C′ i ,t i}, use your own private key to verify and decrypt the signature and ciphertext, and if successful, you will eventually receive the message m i .

[0088] 3. Guarantee of the correctness of the present invention

[0089] In order to identify the correctness of the decryption and encryption algorithms, it is necessary to verify h 2,i =h′ 2,i Whether they are equal, we can judge ω′ by comparing the expressions of the two 2,i =ω 2,i Verify whether they are equal. If it is proved that ω′ 2,i and ω 2,i The consistency of (S′ i ,h′ 2,i )=(S i ,h 2,i ) we have:

[0090]

[0091] By L i =(r 2,i -h 2,i )modq, then L i +h 2,i =r 2,i , so the above formula is:

[0092]

[0093] Further proof that the key used in decryption (K′ 1 _len,K′ 2 _len) and the key generated during encryption (K 1 _len,K 2 _len) is consistent. In C′ i =C i Under the premise of 3,i =ω 3,i That is, we have:

[0094]

[0095] In batch message decryption, first let The specific steps for batch verification are as follows:

[0096] Because L i +h 2,i =r 2,i ,so,

[0097] Next order The batch verification steps are as follows:

[0098]

[0099] Therefore, we can get the correct key (K 1 _len,K 2 _len), in the correct generation of plaintext m i In the case of i =C 3,i ||C 4,i ||C 5,i Decryption becomes natural, that is, the decryption algorithm and encryption algorithm are consistent with each other.

[0100] 4. Security of the present invention

[0101] (1) Privacy protection

[0102] Before joining VANET, all vehicles need to submit their real ID to KGC. KGC generates a pseudonym PID for the vehicle based on the vehicle ID. In this way, no third party except KGC can obtain the real ID of the vehicle, thus ensuring the privacy of the vehicle.

[0103] (2) Decentralization

[0104] Different from the centralized database storage method used in traditional intelligent transportation systems, this project adopts a dual-blockchain distributed storage solution, which gets rid of the dependence on a trusted third-party entity database, avoids the potential risk of traditional centralized data storage being vulnerable to centralized malicious attacks, and achieves cost savings in maintenance.

[0105] (3) Non-repudiation

[0106] All information sent by the vehicle will be recorded on the public blockchain, and KGC can find the real $ID$ of the vehicle that sent the information using a pseudonym through the records.

[0107] (4) Defending against forgery attacks

[0108] The private key of the information sender is known only to the sender himself, and the anonymous identity is unknown to any third party except KGC. Therefore, in the signing stage, the attacker cannot impersonate the trusted node in VANET, so the scheme can resist forgery attacks.

[0109] (5) Anti-key attack

[0110] In order to solve the key management problem, KGC only generates part of the private key of the vehicle, and only the vehicle itself knows its own private key. At the same time, the vehicle public key is indirectly generated by the system master private key, and the attacker cannot obtain the system master private key. Therefore, this solution has the characteristics of resisting key attacks.

[0111] 5. Communication Overhead Analysis of the Present Invention

[0112] The message tuple {mi,Ω i ,C i ,t i}, C i =C 2,i ||C 3,i ||C 4,i ,Ω i =(S i ,h 2,i ), S i ,C 2,i ∈G 1 , C 3,i With message m i , the same length, Where |G 1 |=64bypes, t i |=4bytes, the final communication overhead is:

[0113]

[0114] The present invention and existing technical solutions: Shao et al. in "Computer Networks" 2023, 23 "Blockchain-assisted certificateless signcryption for vehicle-to-vehicle communication in VANETs"; Ali et al. in "IEEE Transactions on Vehicular Technology" 2021, 70(6) "Bilinear pairing-based hybrid signcryption for secure heterogeneousvehicular communications"; Hu et al. in "Vehicular Communications》2020, 26 "Secure message classification services through identity-based signcryption with equality test towards the Internet of vehicles"; Kar et al. in "IEEE Transactionson Vehicular Technology" 2024, 73(6) "SL-PPCP: Secure and low-cost privacy-preserving communication protocol for vehicular ad-hoc networks"; Kumar et al. in, "Transactions on Emerging Telecommunications Technologies》2020,31(6)“A securedata transmission protocol for cloud-assisted edge-internet of yhingsenvironment” Hou et al. in “Transactions on Emerging TelecommunicationsTechnologies” 2021, 32(8) “Heterogeneous signcryption scheme supporting equality test from PKI to CLC toward IoT”. The communication overhead comparison is shown in Table 1.

[0115] Table 1. Comparison of communication overhead of various schemes

[0116]

[0117]

[0118] 6. Analysis of the computational overhead of the present invention

[0119] The computational overhead in the signature and decryption process of the present invention is lower than that in the case of a processor equipped with Intel's eighth-generation Core i5 processor, NVIDIA The program was run on a computer with GeForce GTX 1050Ti and 16GB DDR4 memory. The main bilinear pairs defined on the elliptic curve group currently used are Weil pairs, Tate pairs, Ate pairs, and Rate pairs. This program selected the Rate pair with better security and higher calculation rate. Finally, the running time of the cryptographic operations required in the scheme was obtained. T m1 Represents calculation G 1 The time required for a scalar multiplication, T ex Represents calculation G 1 The time required for one exponentiation operation is Representative point to group G 1 The time required for mapping, T m2 Represents calculation G 2 The time required for a scalar multiplication, T′ ex Represents calculation G T The time required for one power operation, T pb The time required to calculate a bilinear pairing, the running time of the above ciphers will be recorded in Table 2. The comparison of the computational overhead of the signcryption and decryption process of this scheme and the decryption of batch messages with the existing schemes mentioned above is shown in Table 3 and Table 4 respectively:

[0120] Table 2. Run time of various cryptographic operations

[0121]

[0122] Table 3 Comparison of message signature and decryption overhead between various schemes and the present invention

[0123]

[0124] Table 4 Comparison of the batch message decryption overhead between various schemes and the present invention

[0125]

[0126] Figure 4 This is a comparison chart of the computational overhead of executing the message signcryption process of the present invention and other schemes. For one message signcryption, the present invention only needs to execute G twice. 1 A scalar multiplication and two G TA power operation, i.e., 2T m1 +2T′ ex = 1.34 ms, and the signature encryption calculation overhead is on average reduced by 82.96% compared with the other six schemes.

[0127] Figure 5 The comparison chart of the calculation overhead generated by the present invention and other schemes in the process of performing message signature encryption. For one message decryption, the present invention needs to perform two bilinear pair operations and two G T A power operation, i.e., 2T pb +2T′ ex = 8.22 ms, and the decryption calculation overhead is on average reduced by 13.08% compared with the other six schemes.

[0128] Figure 6 The comparison chart of the calculation overhead generated by the present invention and other schemes in the process of performing batch message signature encryption. When performing fifty message decryptions, the present invention needs to perform fifty-one bilinear pair operations and two G T A power operation, i.e., 51T pb +2T′ ex = 181.27 ms, and the decryption calculation overhead is on average reduced by 45.96% compared with the other six schemes. It can be seen that the present invention has more obvious advantages in the VANET environment with a large amount of data.

Claims

1. A certificateless signature encryption method in vehicle-mounted ad hoc network communication, characterized in that Follow these steps: (S01): The key generation center KGC generates a pair of system public keys P during system initialization and vehicle identity registration. pub1 , P pub2 and master private keys s1 and s2, and generate two hash functions H1(Z,q) and H2(Z,q); the trusted vehicle user V i You need to submit your vehicle ID to KGC i , KGC uses its ID i Generate the identifier hid with the randomly generated private key i Generate a corresponding anonymous identity PID for it i ; KGC uses the generated PID i For registered trusted vehicles V i Assign a pair of vehicle public keys Q 1,i , Q 2,i and a pair of partial private keys d 1,i ,d 2,i ; KGC will eventually upload the public key pair of each trusted user's vehicle to the alliance blockchain; (S02): Vehicle V i Call the key encapsulation algorithm in the SM9 cryptographic algorithm and apply it to the vehicle V i The session key generated between the vehicle V i Using the key derivation function KDF, the random number r generated by yourself 1,i And obtain vehicle V from the alliance blockchain j The public key Q 1,i The session key K is obtained through the corresponding calculation 1,i And the session ciphertext C 1,i ; Vehicle V j After receiving the session key and ciphertext, the key decryption algorithm in the SM9 cipher is called, and the partial private key assigned by KGC and the KDF function are used to verify and calculate the session key; (S03): Trusted Vehicle V i As the message sender, use the partial private key pair distributed by KGC and select the random number Autonomous complete private key pair {D 1,i ,D 2,i }; Vehicle V i Then two random numbers are selected to encrypt the message m by calling the message encryption algorithm, Enc encryption algorithm and message authentication code function MAC in the SM9 cryptographic algorithm. i Encryption is performed to obtain the ciphertext C i =C 2,i ||C 3,i ||C 4,i , SignatureΩ i =(S i ,h 2,i ) and key elements ω 2,i ,ω 3,i , and finally the message tuple {m i ,Ω i ,C i ,t i }Send to receiving vehicle V j , where t i is the vehicle V i Broadcast tuple {m i ,Ω i ,C i ,t i } moment; (S04): Trusted Vehicle V j As a message receiver, it receives the message tuple {m i ′,Ω i ′,C i ′,t i }, the vehicle V j First, check the timeliness of the message, then call the message decryption algorithm, Dec symmetric decryption algorithm and message authentication code function MAC in the SM9 cryptographic algorithm to verify the message signature. In this process, two key elements ω′ can be obtained 2,i ,ω′ 3,i And decrypt the ciphertext to obtain the secure, reliable, and untampered plaintext message m i ; (S05): Receive vehicle V j Received from different vehicles V1, V2, ..., V n The message tuples sent are {m′1,Ω′1,C′1,t1},{m′2,Ω′2,C′2,t2},...{m′ n ,Ω′ n , C′ n , t n }; Vehicle V j First check the timeliness of the message, then V j The element {ω′ 2,1 ,ω′ 3,1 },{ω′ 2,2 ,ω′ 3,2 }, ..., {ω′ 2,n ,ω′ 3,n } respectively perform aggregation processing to obtain elements W1 and W2; then vehicle V j The two elements obtained are verified, and after the verification is passed, the corresponding ciphertext decryption process is performed.

2. According to claim 1, a certificateless signature encryption method in vehicle-mounted self-organizing network communication is characterized in that The step (S01) is carried out according to the following steps: (1) System initialization: The key generation center (KGC) selects three cyclic groups of order q, which are two additive cyclic groups (G1, +) and (G2, +). There exists a homomorphic mapping ψ from G2 to G1, such that ψ(P2) = P1, and there is a bilinear pairing e:G1×G2→G T ; G T is a multiplicative cyclic group; P1 and P2 are generators of G1 and G2 respectively; the inputs of cryptographic functions H1(Z,q) and H2(Z,q) are both Z and integer q, and the outputs are h1∈[1,q-1] and h2∈[1,q-1] respectively, where q is a large prime number and Z represents a bit string; (2) System parameter generation: KGC randomly selects s1,s2∈Z q * Calculate the element P in G2 pub1 =s1P2,P pub2 =s2P1,P pub1 and P pub2 is a pair of system public keys; KGC calculates G T The element g1=e(P1,P pub1 ), g2=e(P2,P pub2 ), then set the parameters params = {q, P1, P2, P pub1 ,P pub2 ,g1,g2,H1,H2,G1,G2,G T } Publish the parameters on VANET and store s1,s2 secretly; (3) Vehicle information generation: KGC randomly generates a large byte HID i Represents a trusted vehicle V i Private key generates identifier and calculates PID i =h 1,i , where h 1,i =H(ID i ||hid i ,q),PID i Give the vehicle V for KGC i Generated anonymous identity; KGC calculates t 1,i =h 1,i +s1,t′ 1,i =h 1,i +s2 if t 1,i ,t′ 1,i ≠0, then calculate t 2,i =s1 / t 1,i , t′ 2,i =s2 / t 2,i , then calculate: d 1,i , d 2,i As a vehicle V i Partial private key pair; Q 1,i ,Q 2,i As a vehicle V i Public key pair; finally KGC sends a public key pair to the trusted vehicle V i Send key i ={d 1,i ,d 2,i ,Q 1,i ,Q 2,i ,PID i }.

3. According to claim 1, a certificateless signature encryption method in vehicle-mounted ad hoc network communication is characterized in that The key encapsulation and decapsulation algorithm based on the SM9 cryptographic algorithm described in step (S02) comprises the following steps: (1) Session key encapsulation V i Generate a random number r 1,i ∈Z q * , and calculate the element C in G1 at the same time 1,i =r 1,i Q 1,j , and then C 1,i The data type of V is converted to a bit string; i Calculate G T Elements in And ω 1,i Convert data type to bit string; calculate K 1,i =KDF(C 1,i ||ω 1,i ||ID i ,klen1), if K 1,i If it is a string of all zero bits, return to (1) to regenerate the random number r 1,i Calculate; otherwise V i Output (K 1,i ,C 1,i ), where K 1,i The encapsulated key, C1,i is KGC and the vehicle V i The corresponding ciphertext generated by the session; finally V i (K 1,i ,C 1,i ) is sent to the corresponding vehicle V j ; (2) Session key decryption Vehicle V j Received (K 1,i ,C 1,i ) and then verify the ciphertext C 1,i ∈G1 is true, if not, exit and report to KGC; if true, then vehicle V j Calculate G T The element ω′ in 1,i =e(C 1,i ,d 1,j ), and at the same time 1,i The data type is converted into a bit string; the received C 1,i Convert the data type to a bit string and calculate V i Encapsulated key K′ 1,i =KDF(C 1,i ||ω′ 1,i ||ID i ,klen1), KDF is the key derivation function, if K′ 1,i All 0 or K 1,i =K′ 1,i If it is not established, then an error will be reported and the vehicle will exit; otherwise, the vehicle V i Securely accept the session key K 1,i .

4. According to claim 1, a certificateless signature encryption method in vehicle-mounted ad hoc network communication is characterized in that The message encryption algorithm based on the SM9 cryptographic algorithm described in step (S03) comprises the following steps: (1) Private key generation Vehicle V i Select random number V i calculate D 1,i ,D 2,i As a vehicle private key pair; (2) Message Signcryption 1) Vehicle V i Select random number Calculate G1 and G separately T The element C in 3,i =r 3,i Q 1,j , 2) Calculate h 2,i =H2(m i ||ω 2,i ,q),L i =(r 2,i -h 2,i )modq; if L i = 0, then return to (1) and reselect the random number r 2,i ; Otherwise calculate K 2,i =KDF(C 2,i ||ω 3,i ||ID j ,klen)=K1_len||K2_len, the input klen represents the length of the secret key; 3) Calculate S i =L i ·D 1,i , let Ω i =(S i ,h 2,i ), calculate C 4,i =Enc(K1_len,m i ), Enc is a symmetric encryption algorithm; calculate C 5,i =MAC(K2_len,C 4,i ), MAC is a message authentication function, the purpose is to prevent the input data from being maliciously tampered with; 4) Finally output the ciphertext C i =C 3,i ||C 4,i ||C 5,i ; and {m i ,Ω i ,C i ,t i }Send to other vehicles V j , where t i is the vehicle V i Broadcast tuple {m i ,Ω i ,C i ,t i }; at the same time, the broadcast tuple will also be stored on the public chain for other trusted vehicles to obtain.

5. The certificateless signature encryption method in vehicle-mounted ad hoc network communication according to claim 1 is characterized in that The message decryption algorithm based on the SM9 cryptographic algorithm described in step (S04) comprises the following steps: (1) Check the transmission delay Vehicle V j Accept the message tuple {m′ i ,Ω′ i ,C′ i ,t i }Vehicle based on arrival time t j and the previous moment t i To check the transmission delay; first the vehicle V j Judgement j -t i > Δt is true, if true, directly refuse to accept the message tuple, otherwise the message recipient V j Execute the following steps, where Δt is the specified maximum transmission delay; (2) Message decryption 1) Vehicle V j Verify h′ 2,i ∈Z q * , S i ′∈G1 is true, if not, the verification fails, otherwise from C′ i Take out C′ 2,i , verify C′ 2,i ∈G1 is true, if not, report to KGC, otherwise: Calculate G T Mediumω′ 3,i =e(C′ 2,i ,D 2,i ), u i =e(S′ i ,Q 2,i ); 2) Calculate K′ 2,i =KDF(C′ 2,i ||ω′ 3,i ||ID j ,klen)=K1′_len||K2′_len,ω′ 2,i =u i ·t i ; 3) Calculate h 2,i ′=H2(m′ i ||ω′ 2,i ,q), check h 2,i =h′ 2,i Is it true? If not, report an error and report to KGC. Otherwise, calculate m′ i =Dec(K1′_len,C′ 3,i ), Dec is a symmetric decryption algorithm; 4) Calculate f i =MAC(K2′_len,C′ 3,i ), from C′ i Take out C′ 3,i , judge f i =C′ 4,i Is it true? If not, exit and report to KGC, otherwise output message m' i .

6. The certificateless signature encryption method in vehicle-mounted ad hoc network communication according to claim 1 is characterized by: The message decryption algorithm based on the SM9 cryptographic algorithm described in step (S05) comprises the following steps: (1) Check the transmission delay When receiving vehicle V j Received from different vehicles V1, V2, ..., V n The message tuples sent are {m′1,Ω′1,C′1,t1},{m′2,Ω′2,C′2,t2},...,{m′ n ,Ω′ n ,C′ n ,t n }; The vehicle first checks the timeliness of the message. If it exceeds the specified maximum transmission delay, the message is rejected. Otherwise, the receiver starts to recover the message; Vehicle V j Accept each message array {m′ i ,Ω′ i ,C′ i ,t i }; (2) Batch message decryption 1) Vehicle V j Verify that {Ω1, Ω n } The elements in S1′,...S n ′∈G1 is true, if not, the verification fails, otherwise, from each receiving tuple C i Take out C2 from ' ,i , verify C2′ ,i ∈G1 is true, if not, report to KGC, otherwise: If the message is restored, the message recovery fails. Otherwise: 3) Calculate K′ for each message tuple separately 2,i =KDF(C′ 2,i ||ω′ 3,i ||ID j ,klen)=K1′_len||K2′_len; 4) Calculate m′ separately i =Dec(K1′_len,C′ 3,i ), restore the plaintext message, Dec is the symmetric decryption algorithm; 5) Calculate f separately i =MAC(K2′_len,C′ 3,i ), from each tuple containing C′ i Take out C′ 4,i , judge f i =C′ 4,i Is it true? If not, exit and report to KGC, otherwise output the message {m′1,......,m′ n }.

Citation Information

Patent Citations

  • V2X identity authentication method based on SM9

    CN113691958A

  • Vehicle-mounted network connection equipment and system based on IBC encryption system and communication method of vehicle-mounted network connection equipment and system

    CN114501437A

  • Conditional privacy protection batch authentication method and system based on aggregation signature in VANET

    CN118714559A

Cited By

  • Prevention of information leakage through signature

    US12609836B2

  • Extraction of data in a mutually distrustful environment

    US12739130B2

  • Extraction of data in a mutually distrustful environment

    US20250384165A1