Internet of vehicles identity authentication method of alliance chain
By adopting a hierarchical identity authentication method based on alliance chain in the Internet of Vehicles environment, using RSU for local rapid authentication, combined with elliptic curve cryptography and pseudonym mechanism, the problem of difficulty in guaranteeing security and privacy in the existing technology and large computing and communication overhead is solved, and efficient and secure Internet of Vehicles identity authentication is achieved.
Patent Information
- Application Number
- CN202510268210.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-05-23
AI Technical Summary
When facing security threats such as counterfeit attacks and replay attacks, existing Internet of Vehicle Identity Authentication methods are difficult to ensure security and privacy. At the same time, the calculation and communication overhead are large and the suitability is poor.
The layered Internet of Vehicle Identity Authentication method based on the alliance chain is adopted, and a three-layer architecture is designed, and the RSU at the roadside facility layer is used for local rapid authentication, combining the elliptic curve cryptography mechanism and pseudonym mechanism to achieve vehicle anonymity, and maintain the vehicle status through sparse Merkel trees to reduce calculation overhead.
It significantly improves the efficiency and security of Internet of Vehicle Identity Authentication, reduces computing and communication overhead, and makes it more suitable for deployment in resource-constrained Internet of Vehicles environments.
Smart Images

Figure CN120034391A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Vehicles identity authentication, and in particular to a layered Internet of Vehicles identity authentication method based on an alliance chain. Background Art
[0002] In the Internet of Vehicles environment, due to the frequent interaction between vehicles and infrastructure, as well as the wireless transmission communication method, the Internet of Vehicles system is vulnerable to multiple security threats such as impersonation attacks, replay attacks, and public key replacement attacks. Attackers can forge vehicle identity information and impersonate legitimate vehicles to spread false data, thereby causing damage to traffic safety. In addition, the Internet of Vehicles system involves a large amount of sensitive information such as user personal data and vehicle driving data. If this data is obtained by unauthorized persons, it will have a serious impact on the user's privacy and may even endanger personal safety.
[0003] Existing distributed authentication schemes for Internet of Vehicles still have the following shortcomings: Message unlinkability is difficult to ensure: In order to achieve unlinkability between two adjacent messages sent by the same vehicle, existing schemes usually introduce attribute-based encryption technology, or adopt a method where the vehicle changes the public key every time it sends a message, which brings about high computational overhead. Low authentication efficiency: Existing schemes often need to perform a large number of cryptographic operations when performing identity authentication, especially when dealing with large-scale vehicles, the authentication delay increases significantly. High communication overhead: Some schemes need to transmit a large amount of additional authentication information when achieving anonymity and untraceability, resulting in a heavy communication load.
[0004] Therefore, a new IoV authentication method is needed that can ensure security and privacy while reducing computational and communication overheads, making it more suitable for deployment in resource-constrained IoV environments. Summary of the invention
[0005] In view of the defects of the above-mentioned Internet of Vehicles identity authentication method, the present invention provides a layered Internet of Vehicles identity authentication method based on alliance chain. The present invention uses alliance chain technology to realize decentralized distributed authentication, designs a three-layer identity authentication method, and uses the RSU of the roadside facility layer as a light node for local fast authentication, which effectively solves the single point failure problem in traditional centralized authentication. On this basis, a cryptographic mechanism based on elliptic curves is used for identity authentication, and a pseudonym mechanism and random numbers are combined to achieve vehicle anonymity. The vehicle status is maintained through batch authentication and SMT (sparse Merkel tree), avoiding the high computational overhead caused by complex cryptographic operations, and significantly improving the authentication efficiency of the system in large-scale Internet of Vehicles scenarios. The specific steps are as follows:
[0006] (1) System initialization
[0007] (a) TA acts as the trust management layer and selects global system parameters:
[0008] Choose large prime numbers p and q;
[0009] (b) Choose an additive cyclic group G of order q with generator P;
[0010] (c) Choose an elliptic curve y of order q 2 =x 3 +ax+b(mod q), where a,b∈F p And; meet 4a 3 +27b 2 (mod q)≠0
[0011] (d) Random selection number As the master private key of the system, calculate PU ta =s·P system master public key;
[0012] (e) Choose a one-way hash function H:
[0013] (f) TA publishes public parameters params = {p, q, G, P, PU ta ,H()}
[0014] (2) Vehicle Registration
[0015] (a) The vehicle owner prepares the MAC address code, VIN vehicle identification code, and selects a random number r k ;
[0016] (b) Calculation T k =H(ID v ||r k )
[0017] (c) Generate a key pair and select a private key Calculate the public key PU v =d v ·P
[0018] (d) Vehicle configuration registration request Send to the nearest TA, where TS v Is the timestamp.
[0019] (e) TA uses the private key to decrypt and obtain M 1 , generate a pseudonymous PID for the vehicle v =H(ID v ||s), record the real identity and pseudo identity Map (PID v →ID v ) mapping, and anonymous protection of vehicle identity is achieved by generating a pseudo ID.
[0020] (f) Create blockchain transaction tx= <PID v ,PU v ,TS v >, record block index BI v .
[0021] (g) Return the registration certificate M 2 ={PID v ,BI v ,TS v}.
[0022] (3) Roadside unit registration
[0023] (a) RSU selects a unique ID RSU , and timestamp TS rsu .
[0024] (b) RSU sends a registration request Send to the nearest TA.
[0025] (c) TA uses the private key to decrypt and obtain M 3 , generate a public key PU for RSU RSU =ID RSU ·s·P, private key PK RSU =H(PU RSU ·s).
[0026] (d) Create blockchain transaction tx= <PU RSU ,ID RSU >, record block index BI rsu .
[0027] (e) Return the registration certificate M 4 = {PU RSU ,PK RSU ,BI rsu ,TS TA}.
[0028] (4) Pre-certification stage
[0029] (a) User identity authentication, input PID′ v ,VIN′,OBU extracts MAC address and calculates parameters Verify T′ k =H(PID′ v ||r′ k )? =T k .
[0030] (5) Certification stage
[0031] (a) Vehicle selection random number
[0032] (b) Vehicle calculation parameters P k =r v ·PU RSU =(P k _x,P k _y),Q k =r v ·P,
[0033] (c) Send authentication request auth_req = {Q k ,T k ,I k ,PU v ,TS 1}Give nearby RSU
[0034] (d) RSU first checks ΔT = TS now -TS 1 <T threshold
[0035] (e) RSU recovery verification parameter P′ k =Q k ·PK RSU , By querying the blockchain index BI′ v , verify PU v Are they equal? Then calculate position = H (PID ' v )Quickly query the vehicle status information. If the vehicle information is found on SMT, the authentication request is rejected. SMT refers to Sparse Merkle Tree, which is a special type of Merkle Tree that is mainly used to efficiently store and verify sparse data sets. We use it to save the list of revoked vehicles. The root value is obtained by calculating the hash value in the tree. The position refers to the value obtained by hash calculation. If the vehicle exists in SMT, it can be quickly located by the position value, which is convenient for query.
[0036] (6) Message Signing Phase
[0037] (a) Vehicle V i Select its anonymous identity PID vi and the corresponding private key d vi
[0038] (b) Using the block index BI stored in the OBU v
[0039] (c) For message m i, vehicle selection random number
[0040] (d) Calculation:
[0041] A i =γ i ·P
[0042] η i =H(PID vi ||m i ||BI v ||A i ||TS vi )
[0043] Y i =η i A i
[0044] δ i =(d vi +η i γ i )mod q
[0045] (e) Encrypt the message using the public key of the nearby RSU,
[0046] (f) Send message signature tuple {m i ,Bi v ,A i ,S i ,TS vi}Give the recipient RSU.
[0047] (7) Message Authentication Phase
[0048] (a) Timestamp verification: Check |TS now -TS vi | <T threshold If the timeout is exceeded, the message is rejected, where T threshold is the set time threshold.
[0049] (b) Alliance chain verification:
[0050] RSU according to BI vi Get the sender's public key PU from the consortium chain vi and PID vi , and query whether the SMT tree contains PID vi If it does not exist, it means the vehicle is legal.
[0051] (c) Signature Verification:
[0052] Calculate δ i ·P?=PU vi+Y i
[0053] (d) If all verifications pass, the message is accepted; otherwise, it is rejected.
[0054] (8) Batch certification stage
[0055] (a) RSU monitors the vehicle density within the communication range in real time.
[0056] (b) When the number of messages received per unit time exceeds the threshold n_threshold, batch authentication is triggered.
[0057] (c) RSU collects n message signature tuples to be verified: {m i ,BI v ,A i ,S i ,TS vi} i=1,2,3,…,n
[0058] (d) Timestamp Packet Verification:
[0059] Check all messages |TS now -TS vi | <T threshold , remove the timed-out messages from the batch.
[0060] (e) Alliance chain status verification:
[0061] Find all BI v Corresponding PID v , then use SMT for fast query, if PID v If it exists in the SMT, it means that the vehicle has been revoked of its legal status and removed from the batch certification message.
[0062] (f) Batch Status Verification:
[0063] According to each PID vi Calculate position = H(PID vi ), obtain the corresponding SMT from the alliance chain to see whether there are these vehicle nodes, and remove the messages with invalid status.
[0064] (g) Select a random number: i=1,2,...,nExecute batch verification equation:
[0065] (8) Vehicle cancellation stage
[0066] (a) Revoke initiated by RSU, revoke_info_req = Sign rsu {PIDvi ,PU vi ,TS},
[0067] (b) TA verifies the identity of the party submitting the request. If it is legitimate, it constructs the SMT tree node position = H (PID vi ||PU vi ), and then add the revocation information to the SMT tree. Update the hash values of all relevant path nodes of the SMT and calculate the root value of the new SMT.
[0068] (c) Create a revocation transaction tx revoke = <PID vi ,old root ,new root ,TS_rovoke>,TA signs the transaction and then broadcasts the transaction to the alliance chain network. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] Figure 1 It is the overall flow chart of the present invention. DETAILED DESCRIPTION
[0070] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the specific implementation mode, structure, characteristics and effects of the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments.
[0071] A hierarchical Internet of Vehicles identity authentication method based on alliance chain, implementing Figure 1 As shown, it includes the following steps:
[0072] (1) System initialization
[0073] TA acts as the trust management layer and selects global system parameters:
[0074] (a)TA selects large prime numbers p and q;
[0075] (b) Choose an additive cyclic group G of order q with generator P;
[0076] (c) Choose an elliptic curve y of order q 2 =x 3 +ax+b(mod q), where a,b∈F p And; meet 4a 3 +27b 2 (mod q)≠0
[0077] (d) Random selection number As the master private key of the system, calculate PU ta =s·P system master public key;
[0078] (e) Choose a one-way hash function H:
[0079] (f) TA publishes public parameters params = {p, q, G, P, PU ta ,H()}
[0080] (2) Vehicle Registration
[0081] (a) The vehicle owner prepares the MAC address code, VIN vehicle identification code, and selects a random number r k ;
[0082] (b) Calculation T k =H(ID v ||r k )
[0083] (c) Generate a key pair and select a private key Calculate the public key PU v =d v ·P
[0084] (d) Vehicle configuration registration request Send to the nearest TA, where TS v Is the timestamp.
[0085] (e) TA uses the private key to decrypt and obtain M 1 , generate a pseudonymous PID for the vehicle v =H(ID v ||s), record the real identity and pseudo identity Map (PID v →ID v )’s mapping.
[0086] (f) Create blockchain transaction tx= <PID v ,PU v ,TS v >, record block index BI v .
[0087] (g) Return the registration certificate M 2 ={PID v ,BI v ,TS v}.
[0088] (3) Roadside unit registration
[0089] (a) RSU selects a unique ID RSU , and timestamp TS rsu .
[0090] (b) RSU sends a registration request Send to the nearest TA.
[0091] (c) TA uses the private key to decrypt and obtain M 3 , generate a public key PU for RSU RSU =ID RSU ·s·P, private key PK RSU =H(PU RSU ·s).
[0092] (d) Create blockchain transaction tx= <PU RSU ,ID RSU >, record block index BI rsu .
[0093] (e) Return the registration certificate M TA→RSU = {PU RSU ,PK RSU ,BI rsu ,TS TA}.
[0094] (4) Pre-certification stage
[0095] (a) User identity authentication, input PID′ v ,VIN′,OBU extracts MAC address and calculates parameters Verify T′ k =H(PID′ v ||r′ k )? =T k .
[0096] (5) Certification stage
[0097] (a) Vehicle selection random number
[0098] (b) Vehicle calculation parameters P k =r v ·PU RSU =(P k _x,P k _y),Q k =r v ·P,
[0099] (c) Send authentication request auth_req = {Q k ,T k ,I k ,PU v ,TS 1}Give nearby RSU
[0100] (d) RSU first checks ΔT = TS now -TS1 <T threshold
[0101] (e) RSU recovery verification parameter P′ k =Q k ·PK RSU , By querying the blockchain index BI′ v , verify PU v Are they equal? Then calculate position = H (PID ' v )Quickly query the vehicle status information. If the vehicle information is found on the SMT, the authentication request is rejected.
[0102] (6) Message Signing Phase
[0103] (a) Vehicle V i Select its anonymous identity PID vi and the corresponding private key d vi
[0104] (b) Using the block index BI stored in the OBU v
[0105] (c) For message m i , vehicle selection random number
[0106] (d) Calculation:
[0107] A i =γ i ·P
[0108] η i =H(PID vi ||m i ||BI v ||A i ||TS vi )
[0109] Y i =η i A i
[0110] δ i =(d vi +η i γ i )mod q
[0111] (e) Encrypt the message using the public key of the nearby RSU,
[0112] (f) Send message signature tuple {m i ,BIv ,A i ,S i ,TS vi}Give the recipient RSU.
[0113] (7) Message Authentication Phase
[0114] (a) Timestamp verification: Check |TS now -TS vi | <T threshold If the timeout is exceeded, the message is rejected, where T threshold is the set time threshold.
[0115] (b) Alliance chain verification:
[0116] RSU according to BI vi Get the sender's public key PU from the consortium chain vi and PID vi , and query whether the SMT tree contains PID vi If it does not exist, it means the vehicle is legal.
[0117] (c) Signature Verification:
[0118] Calculate δ i ·P? =PU vi +Y i
[0119] (d) If all verifications pass, the message is accepted; otherwise, it is rejected.
[0120] (8) Batch certification stage
[0121] (a) RSU monitors the vehicle density within the communication range in real time.
[0122] (b) When the number of messages received per unit time exceeds the threshold n_threshold, batch authentication is triggered.
[0123] (c) Maintain an authentication cache pool to store messages to be verified.
[0124] (d) RSU collects n message signature tuples to be verified: {m i ,BI v ,A i ,S i ,TS vi} i=1,2,3,…,n
[0125] (e) Timestamp Packet Verification:
[0126] Check all messages |TS now -TS vi | <T threshold, remove the timed-out messages from the batch.
[0127] (f) Alliance chain status verification:
[0128] Find all BI v Corresponding PID v , then use SMT for fast query, if PID v If it exists in the SMT, it means that the vehicle has been revoked of its legal status and removed from the batch certification message.
[0129] (g) Batch Status Verification:
[0130] According to each PID vi Calculate position = H(PID vi ), obtain the corresponding SMT from the alliance chain to see whether there are these vehicle nodes, and remove the messages with invalid status.
[0131] (h) Select random number: i=1,2,...,nExecute batch verification equation:
[0132] (8) Vehicle cancellation stage
[0133] (a) Revoke initiated by RSU, revoke_info_req = Sign rsu {PID vi ,PU vi ,TS},
[0134] (b) TA verifies the identity of the party submitting the request. If it is legitimate, it constructs the SMT tree node position = H (PID vi ||PU vi ), and then add the revocation information to the SMT tree. Update the hash values of all relevant path nodes of the SMT and calculate the root value of the new SMT.
[0135] (c) Create a revocation transaction tx revoke = <PID vi ,old root ,new root ,TS_rovoke>,TA signs the transaction and then broadcasts the transaction to the alliance chain network.
Claims
1. A hierarchical Internet of Vehicles identity authentication method based on alliance chain, characterized by: (1) The system adopts a three-layer architecture design, including a trust management layer where the TA is responsible for system initialization and key management and maintaining the alliance chain; a roadside facility layer where the RSU acts as a light node and is responsible for rapid authentication in local areas; The vehicle layer is supported by smart vehicles equipped with OBU to support identity authentication and message signing. This layered architecture realizes decentralized distributed authentication, avoiding the single point failure risk of traditional centralized authentication. At the same time, all authentication behaviors are permanently recorded on the alliance chain and jointly supervised. (2) During the vehicle registration phase, the vehicle MAC address, VIN vehicle identification code, and random number r are integrated into the vehicle registration code. k , calculate the vehicle's unique ID v , and TA generates a pseudonym PID for the vehicle v , record the mapping relationship and record the registration information in the alliance chain, achieving a balance between the anonymity and traceability of the vehicle identity; (3) A two-stage authentication mechanism is adopted in the authentication phase, including the pre-authentication phase to verify the identity information entered by the user, and the formal authentication phase to achieve two-way authentication between the vehicle and the RSU. The batch verification mechanism and SMT are used to maintain the certificate status, thereby improving system efficiency.
2. According to the alliance chain-based hierarchical Internet of Vehicles identity authentication method of claim 1, the steps are as follows: (1) System initialization TA acts as the trust management layer and selects global system parameters: (a) Select large prime numbers p and q; (b) Choose an additive cyclic group G of order q with generator P; (c) Choose an elliptic curve y of order q 2 =ax 3 +bx(mod q), where a,b∈F p And; meet 4a 3 +27b 2 (modq)≠0. (d) Random selection number As the master private key of the system, calculate PU ta =s·P system master public key; (e) Choose a one-way hash function H: (f) TA publishes public parameters params = {p, q, G, P, PU ta ,H()} (2) Vehicle Registration (a) The vehicle owner prepares the MAC address code, VIN vehicle identification code, and selects a random number r k ; (b) Calculation T k =H(ID v ||r k ) (c) Generate a key pair and select a private key Calculate the public key PU v =d v ·P (d) Vehicle configuration registration request Send to the nearest TA, where TS v Is the timestamp. (e) TA uses the private key to decrypt M1 and generate a pseudonym PID for the vehicle v =H(ID v ||s), record the real identity and pseudo identity Map (PID v →ID v )’s mapping. (f) Create blockchain transaction tx= <PID v ,PU v ,TS v >, record block index BI v . (g) Return the registration certificate M2 = {PID v ,BI v ,TS v }. (3) Roadside unit registration (a) RSU selects a unique ID RSU , and timestamp TS rsu . (b) RSU sends a registration request Send to the nearest TA. (c) TA uses the private key to decrypt M3 and generate the public key PU for RSU RSU =ID RSU ·s·P, private key PK RSU =H(PU RSU ·s). (d) Create blockchain transaction tx= <PU RSU ,ID RSU >, record block index BI rsu . (e) Return the registration certificate M TA→RSU = {PU RSU ,PK RSU ,BI rsu ,TS TA }. (4) Pre-certification stage (a) User identity authentication, input PID′ v ,VIN′,OBU extracts MAC address and calculates parameters Verify T′ k =H(PID′ v ||r′ k )? =T k . (5) Certification stage (a) Vehicle selection random number (b) Vehicle calculation parameters P k =r v ·PU RSU =(P k _x,P k _y),Q k =r v ·P, (c) Send authentication request auth_req = {Q k ,T k ,I k ,PU v ,TS1} to nearby RSU (d) RSU first checks ΔT = TS now -TS1 <T threshold (e) RSU recovery verification parameter P′ k =Q k ·PK RSU , By querying the blockchain index BI′ v , verify PU v Are they equal? Then calculate position = H (PID ' v )Quickly query the vehicle status information. If the vehicle information is found on the SMT, the authentication request is rejected. (6) Message Signing Phase (a) Vehicle V i Select its anonymous identity PID vi and the corresponding private key d vi (b) Using the block index BI stored in the OBU v (c) For message m i , vehicle selection random number (d) Calculation: A i =c i ·P η i =H(PID vi ||m i ||BI v ||A i ||TS vi ) AND i =η i TO i d i =(d vi +n i c i )mod q (e) Encrypt the message using the public key of the nearby RSU, (f) Send message signature tuple {m i ,BI v ,A i ,S i ,TS vi }Give the recipient RSU. (7) Message Authentication Phase (a) Timestamp verification: Check |TS now -TS vi | <T threshold If the timeout is exceeded, the message is rejected, where T threshold is the set time threshold. (b) Alliance chain verification: RSU according to BI vi Get the sender's public key PU from the consortium chain vi and PID vi , and query whether the SMT tree contains PID vi If it does not exist, it means the vehicle is legal. (c) Signature Verification: Calculate δ i ·P?=PU vi +Y i (d) If all verifications pass, the message is accepted; otherwise, it is rejected. (8) Batch certification stage (a) RSU monitors the vehicle density within the communication range in real time. (b) When the number of messages received per unit time exceeds the threshold n_threshold, batch authentication is triggered. (c) RSU collects n message signature tuples to be verified: {m i ,BI v ,A i ,S i ,TS vi }i=1,2,3,…,n (d) Timestamp Packet Verification: Check all messages |TS now -TS vi | <T threshold , remove the timed-out messages from the batch. (e) Alliance chain status verification: Find all BI v Corresponding PID v , then use SMT for fast query, if PID v If it exists in the SMT, it means that the vehicle has been revoked of its legal status and removed from the batch certification message. (f) Batch Status Verification: According to each PID vi Calculate position = H(PID vi ), obtain the corresponding SMT from the alliance chain to see whether there are these vehicle nodes, and remove the messages with invalid status. (g) Select random number: Perform batch verification equation: (8) Vehicle cancellation stage (a) Revoke initiated by RSU, revoke_info_req = Sign rsu {PID vi ,PU vi ,TS}, (b) TA verifies the identity of the party submitting the request. If it is legitimate, it constructs the SMT tree node position = H (PID vi ||PU vi ), and then add the revocation information to the SMT tree. Update the hash values of all relevant path nodes of the SMT and calculate the root value of the new SMT. (c) Create a revocation transaction tx revoke = <PID vi ,old root ,new root ,TS_rovoke>,TA signs the transaction and then broadcasts the transaction to the alliance chain network.