Internet of vehicles cross-domain authentication method based on block chain and self-sovereign identity
By adopting cross-domain authentication methods based on blockchain and self-sovereign identity in the Internet of Vehicles system, and using technologies such as alliance chains and sparse Merkel trees, the problems of cross-domain authentication delay and privacy data leakage in the Internet of Vehicles system are solved, and efficient and secure cross-domain authentication is achieved.
Patent Information
- Application Number
- CN202311596545.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
Due to its openness and vulnerability, the Internet of Vehicles systems face the challenge of cross-domain authentication. Traditional identity authentication solutions are difficult to effectively solve the problems of cross-domain authentication delay and privacy data leakage.
The Internet of Vehicles cross-domain authentication method based on blockchain and self-sovereign identity is adopted, and a distributed identity management architecture is established through the alliance chain, and a sparse Merkel tree and conditional privacy anonymous signature method is used to realize the distributed sharing and selective disclosure of vehicle identity information, reducing cross-domain authentication delay and enhancing security.
It effectively reduces the delay in cross-domain authentication, enhances the security and privacy protection of the Internet of Vehicles system, and improves the efficiency of identity authentication and the adaptability and scalability of the system.
Smart Images

Figure CN120050052A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and specifically relates to a cross-domain authentication method for the Internet of Vehicles based on blockchain and self-sovereign identity. Technical Background
[0002] The Internet of Vehicles is considered to be one of the most core pillar paradigms of the intelligent transportation system. In the Internet of Vehicles, vehicles can access various services to improve the driving experience and enhance traffic safety, such as route planning queries, road traffic monitoring, point of interest discovery, and emergency event alarms. Compared with the Internet of Things mode, the Internet of Vehicles is a new type of mobile ad hoc network with a dynamic topology structure. Vehicles use dedicated short-range communication or LTE V2X technology to maintain connections with roadside units (RSUs) or other vehicles during high-speed driving. In the mobile state, vehicles can request services from application service providers through RSUs. However, due to the dynamic characteristics of the Internet of Vehicles, such as openness, mobility, and continuous real-time data transmission, it faces inherent security and privacy threats. As Figure 1 shown, this situation reflects the challenges of cross-domain authentication because fast-moving vehicles need to frequently switch services between different security domains. Communication or service request data may be intercepted, tampered with, or forged, and potential adversaries may impersonate authorized vehicles to deceive RSUs to obtain services. Therefore, before the widespread application of the Internet of Vehicles, it is necessary to develop a cross-domain authentication scheme to address these security issues.
[0003] First, due to the inherent openness and vulnerability of the Internet of Vehicles, the authentication scheme must prioritize security and privacy. On the one hand, most traditional authentication schemes are designed for single-domain scenarios and ignore the fact that the movement of vehicles between different domains has become a common phenomenon. On the other hand, RSUs and service providers generally have the characteristics of being honest but curious, and they may obtain sensitive details in the service requests initiated by vehicles, such as location information and home addresses. In addition, external attackers can also obtain the content shared between vehicles and service providers. Second, due to the high-speed mobility of vehicles, an efficient authentication scheme is crucial. Effective cross-domain information sharing plays a vital role in achieving efficient vehicle permission authentication and information verification. In a multi-security domain environment, vehicles often move quickly between these security domains, so it is necessary to frequently perform authentication between different security domains and with RSUs. This dynamic movement will introduce a relatively high communication delay in the cross-domain authentication process, which may lead to the interruption of vehicle network services and increase the computing burden on RSUs.
[0004] Vehicular ad hoc networks (VANETs) typically rely on a public key infrastructure to build an authentication scheme, and trusted certificate authorities are responsible for issuing identity certificates to vehicles. However, many application server providers tend to create their own certificate authorities and provide authentication services for vehicles. The closed nature of multiple security domains makes cross-domain authentication extremely difficult. Multi-party negotiation and mutual trust are required between different autonomous domains to conduct cross-domain authentication. The authentication process is more complex, reducing the adaptability and scalability of the system. Blockchain technology, with its characteristics such as decentralization, anti-tampering, and traceability, has attracted the interest of scholars and is considered to enhance the security of vehicle networks. In a blockchain-based cross-domain authentication scheme, multiple certificate authority servers build a consortium blockchain and maintain a single distributed ledger to assist in identity certificate verification. However, the centralized storage of certificate information raises the possibility of centralized privacy data leakage. Once a blockchain node is attacked, a large amount of privacy data will be leaked. How to integrate blockchain technology into the development of a fully distributed identity management system and a simplified cross-domain authentication process to improve the security of VANET authentication services remains a notable and unsolved challenge. Summary of the Invention
[0005] In view of the openness and vulnerability of VANETs and the problems existing in existing identity authentication technologies, the present invention proposes a cross-domain authentication method for VANETs based on blockchain and self-sovereign identity. This method provides a cross-domain authentication service for high-speed moving vehicles to request application services between different security domains, can realize the distributed sharing of vehicle identity authentication information between different security domains, effectively reduce the cross-domain authentication delay, and at the same time, the vehicle completely owns the control right of the identity information and can selectively disclose the necessary information for cross-domain authentication. The present invention establishes a distributed identity information management architecture based on a consortium chain, stores the identity credential information in the Merkle tree structure in the dynamic accumulator on the consortium chain, and constructs vehicle access credentials using a sparse Merkle tree to avoid the leakage of privacy information during the cross-domain authentication process; uses conditional privacy anonymity method to sign messages, realizes the integrity and credibility of request information transmission through pseudonyms, and supports batch verification of signed messages and revocation of the identity of malicious vehicles. The system parameters and storage space of the present invention are small, and the verification delay is small, which can meet the cross-domain authentication requirements of vehicles in a dynamically changing VANET environment.
[0006] The technical solutions adopted by the present invention to solve the existing problems are as follows:
[0007] The present invention provides a cross-domain authentication method for VANETs based on blockchain and self-sovereign identity, including five stages: cross-domain authentication system initialization stage, vehicle registration stage, access credential generation stage, vehicle cross-domain authentication stage, and vehicle identity revocation stage.
[0008] Phase A: Initialization of the cross-domain authentication system. It is characterized by the fact that each IoV security domain has a key generation center KGC, an identity credential issuer Issuer, and an edge authentication node RSU. The KGC of each IoV security domain will initialize the cross-domain authentication system according to the security parameter λ and generate the global system parameters (q, P, G, PK, H 1 ,H 2 ,H 3 ,H 4 ), and in each security domain D i Generate a public and private key pair (msk i ,mpk i ), where D i Prime represents the i-th domain in the Internet of Vehicles, the prime number q is the order of the additive cyclic group G, P is the generator of G, H 1 ,H 2 ,H 3 ,H 4 There are four hash functions, PK is the system global public key, msk i and mpk i The private key and public key of the ith domain respectively.
[0009] Phase B: Vehicle registration phase, characterized by vehicle V i j Generate your own identity RID j and a public-private key pair (sk j ,pk j ) and use RID j To KGC i Request pseudonym PID j , where V i j represents the i-th vehicle in the i-th domain; then V i j Generate identity credentials using the Merkle tree structure for identity attributes and sign the credentials. i Initiate an identity release request. i Add the verified valid vehicle registration information to f j =H 2 (PID j ,pk j ,Mroot j ) to the dynamic accumulator of the blockchain, where Mroot j The Merkle tree root of the vehicle identity information is not only used for cross-domain sharing and rapid verification of vehicle identity information, but also to avoid any leakage of privacy information.
[0010] Phase C: Access Credential Generation Phase, characterized in that the vehicle can construct access credentials through a sparse Merkle tree structure, selectively disclose the vehicle's identity information to meet the verification requirements of the service authenticator, avoid the leakage of extra identity information, and utilize the pseudonym PID j Anonymously sign the service request message to ensure the reliability and integrity of the message.
[0011] Phase D: Vehicle Cross-Domain Authentication Phase, characterized in that the edge authentication node RSU first checks the time freshness and signature validity of the access request message, secondly uses the sparse Merkle tree to recover the Merkle root of the vehicle identity, verifies the authenticity of the selectively disclosed identity information in the access credential by querying the dynamic accumulator, and adopts a batch message verification method to improve the message verification efficiency.
[0012] Phase E: Vehicle Identity Revocation Phase, characterized in that when vehicle V i j sends illegal service request information or conducts malicious attacks, the KGC i can recover the real identity of the vehicle through the pseudonym PID j terminate the life cycle of the pseudonym, and at the same time revoke the identity credential information that has been published by V i j in the dynamic accumulator.
[0013] The cross-domain authentication method for vehicle networking based on blockchain and self-sovereign identity of the present invention has the following advantages:
[0014] (1) Adopt a consortium blockchain to construct a distributed identity management architecture, realize the sharing of vehicle identity data in multiple security domains, and avoid single point of failure;
[0015] (2) Adopt self-sovereign identity and sparse Merkle tree to realize that the vehicle has full control over privacy information, can flexibly and selectively disclose the identity information to be verified, and avoid the leakage of extra privacy information;
[0016] (3) Utilize the high efficiency of member verification in the dynamic accumulator to transform the vehicle cross-domain identity authentication process into a query process of the dynamic accumulator, and improve the identity authentication efficiency;
[0017] (4) Adopt a conditional privacy anonymous signature method to verify the integrity and credibility of request information transmission through pseudonyms, and support batch verification of signature messages and revocation of the identities of malicious vehicles. Description of the Drawings
[0018] Figure 1 Cross-Domain Authentication Scenario Diagram
[0019] Figure 2 Symbols and Descriptions in this Solution
[0020] Figure 3 Voucher Structure Diagram
[0021] Figure 4 Registration Flowchart
[0022] Figure 5 Sparse Merkle Tree Diagram
[0023] Figure 6 Cross-Domain Authentication Flowchart
[0024] Figure 7 Vehicle Identity Revocation Flowchart Detailed Implementation Manner
[0025] To make the technical means, creative features, achieved purposes, and functions of the implementation of the present invention easy to understand and master, the present invention will be further described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0026] In view of the openness and vulnerability of the vehicle networking and the problems existing in the existing identity authentication technologies, the present invention provides a vehicle networking cross-domain authentication method based on blockchain and self-sovereign identity, including five stages: cross-domain authentication system initialization stage, vehicle registration stage, access voucher generation stage, vehicle cross-domain authentication stage, and vehicle identity revocation stage. The present invention will be described in detail below with reference to the accompanying drawings.
[0027] Stage A: Cross-Domain Authentication System Initialization Stage
[0028] In the cross-domain authentication system initialization stage, global system parameters and domain public and private key pairs are mainly generated. Given the security parameter λ, the cross-domain authentication system is initialized and the global system parameters (q, P, G, PK, H 1 , H 2 , H 3 , H 4 ) of the vehicle networking are generated. The prime number q is the order of the additive cyclic group G, P is the generator of G, and H 1 , H 2 , H 3 , H 4 are four hash functions, PK is the global public key of the system, msk i and mpk i are the private key and public key of the i-th domain respectively. Four one-way hash functions H 1 , H 2 , H 3 , H 4 are selected, where H 1 : H 2 : H 3 : and H 1 : and KGC i generates a public-private key pair (msk i , mpk i ) for each security domain D i , where D i denotes the i-th domain in the vehicle network, and KGC i randomly selects an element as the private key of the domain and calculates s i P as the public-private key of the domain.
[0029] Phase B: Vehicle Registration Phase
[0030] Vehicle key pair and pseudonym generation: Vehicle V i j generates an identity identifier RID j , and randomly selects an element as the private key of the vehicle and calculates s j P as the public key of the vehicle, and then sends the identity identifier to KGC i to request a pseudonym, where V i j is the j-th vehicle in the i-th domain; then, KGC i randomly selects an element and calculates R j = r j P element, and uses R j to generate a pseudonym and returns it to V i j , where LT is the life cycle of the pseudonym;
[0031] Vehicle verifiable identity credential generation: V i j uses the Merkle tree structure for the identity attribute information ATTR j = {attr 1 , attr 2 , …, attr n} to generate the Merkle root Mroot j of the identity information, and constructs the vehicle's verifiable identity credential VC j using Mroot j as the claim of the verifiable credential, and the structure of the credential is as Figure 3 ; then, V i j randomly selects an element and calculates E j = e j P and η j = sk j H4 (PID j ) + e j PH 4 (Mroot j ), and send {PID j , ATTR j , VC j , pk j , η j , E j} to Issue i for identity credential verification and issuance.
[0032] Issue i First, verify the freshness of the message and verify the equality of the verification equation η j P = pk j H 4 (PID j ) + E j H 4 (Mroot j ). If they are equal, it means the message is valid and complete. Generate Mroot' j through ATTR j and verify its equality with Mroot in the message j . If all the above verifications pass, Issue i , as a consensus node of the blockchain, adds f j = H 2 (PID j , pk j , Mroot j ) to the dynamic accumulator on the blockchain and encapsulates (PID j , pk j , ACC, upmsg) in the block for network-wide broadcast, where Acc is the accumulated value and upmsg is the auxiliary information. Otherwise, terminate the current session. The specific vehicle registration process is as shown in Figure 4.
[0033] Phase C: Access Credential Generation Phase
[0034] V i j The selective disclosure service provider verifies the information to be verified, generates a sparse Merkle multi-value proof Mproof j using the sparse Merkle tree structure for the identity attribute information ATTR j,req , and generates a verifiable access credential VC j,req , which includes Mproof j,req and Mroot j . This process can conceal unnecessary sensitive information and retain the complete Mrootj Recovery path, for example Figure 5 The sparse Merkle tree structure shown, the verifiable path of the identity includes Addr, Hash3, and Hash12; secondly, V i j Randomly select an element And calculate U j = u j P, then calculate σ j = H 2 (PID j , U j , VC j,req ) and β j = H 3 (M j,req , PID j , TS j , U j ); finally, V i j Generate the signature information τ j = {U j , δ j} where δ j = sk j σ j + u j β j , then send the service request message {PID j , M j,req , TS j , VC j,req , τ j} to the edge verification node RSU i .
[0035] Phase D Vehicle Cross-Domain Authentication Phase
[0036] RSU i First, check the freshness of the service request message, and then verify the equation δ j P = σ j pk j + U j β j to see if they are equal. If they are equal, it means the message is valid and complete. In addition, use the equation for batch verification of the message to improve the verification efficiency of the message; if the verification of the integrity and freshness of the message both pass, RSU i Use the sparse Merkle Mproof j,req to recover the Merkle root Mroot' i j of the identity information of V j , if the equation Mroot j = Mroot'j Establish, RSU i Query the dynamic accumulator Mroot j Whether it exists. If it exists, then V i j The authentication is passed; otherwise, the current session is terminated. The specific cross-domain authentication process is shown in Figure 6.
[0037] Phase E: Vehicle identity revocation phase
[0038] KGC i By calculating Restore the malicious vehicle V i j 's real identity and terminate V i j 's pseudonym lifecycle; then, KGC i Submit {PID j , R j , LT} to the blockchain, update it through the value of the dynamic accumulator, and revoke the identity credential published by the malicious vehicle V i j The specific cross-domain authentication process is shown in Figure 7.
Claims
1. A cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity, characterized in that, a privacy - protection authentication method for vehicles across multiple security domains is proposed, mainly including the following stages: Phase A: Cross - domain authentication system initialization phase. It is characterized in that in each vehicle - to - everything (V2X) security domain, there is a key generation center (KGC), an identity credential issuer (Issuer), and a roadside unit (RSU). The KGC in each V2X security domain initializes the cross - domain authentication system according to the security parameter λ, generates the system parameters (q, P, G, PK, H 1 ,H 2 ,H 3 ,H 4 ) of the V2X global system, and generates a public - private key pair (msk i ,mpk i ) in each security domain Di, where D i represents the i - th domain in the V2X network. The prime number q is the order of the additive cyclic group G, P is the generator of G, and H 1 ,H 2 ,H 3 ,H 4 are four hash functions, PK is the global public key of the system, msk i and mpk i are the private key and public key of the i - th domain respectively. Phase B: Vehicle registration phase, characterized by vehicle V i j Generate your own identity RID j and a public-private key pair (sk j ,pk j ) and use RID j To KGC i Request pseudonym PID j , where V i j represents the i-th vehicle in the i-th domain; then V i j The identity attributes are generated into an identity certificate using a Merkle tree structure, and after signing the certificate, an identity release request is sent to the Issuer. i Add the verified valid vehicle registration information to f j =H 2 (PID j ,pk j ,Mroot j ) to the dynamic accumulator of the blockchain, where Mroot j The Merkle tree root of the vehicle identity information is not only used for cross-domain sharing and rapid verification of vehicle identity information, but also to avoid any leakage of privacy information. Phase C: Access Credential Generation Phase, characterized in that the vehicle can construct access credentials through a sparse Merkle tree structure, selectively disclose the vehicle's identity information to meet the verification requirements of the service authenticator, avoid the leakage of external identity information, and utilize the pseudonym PID j Anonymously sign the service request message to ensure the reliability and integrity of the message. Stage D: Vehicle cross - domain authentication stage. It is characterized in that the edge authentication node RSU first checks the time freshness and signature validity of the access request message. Secondly, it uses a sparse Merkle tree to recover the Merkle root of the vehicle identity. It verifies the authenticity of the selectively disclosed identity information in the access credential by querying the dynamic accumulator, and adopts a batch message verification method to improve the message verification efficiency. Phase E: Vehicle identity revocation phase, characterized in that when vehicle V i j sends illegal service request information or conducts malicious attacks, the KGC i can recover the real identity of the vehicle through the pseudonym PID j and terminate the life cycle of the pseudonym. At the same time, the identity credential information that V i j has already published in the dynamic accumulator is revoked.
2. The cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity according to claim 1, characterized in that in the cross - domain authentication system initialization stage of Stage A, the specific implementation is as follows: Step 1: Given the security parameter λ, initialize the cross-domain authentication system and generate the system parameters for the entire vehicle network. Select four one-way hash functions H 1 , H 2 , H 3 , H 4 , where H 1 : H 2 : H 3 : and H 1 : Step 2: KGC i Initialize the i-th domain, and randomly select an element as the private key of the domain, and calculate s i P as the public-private key of the domain.
3. The cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity according to claim 1, characterized in that in the vehicle registration stage of Stage B, the specific implementation is as follows: Step 1: Vehicle V i j Generate its own identity identifier RID j , and randomly select an element as the private key of the vehicle, and calculate s j P itself as the public key of the vehicle, and then send the identity identifier to the KGC i Request a pseudonym, where V i j is the j-th vehicle in the i-th domain; Step 2: KGC i Randomly select an element and calculate R j = r j P element, then generate a kana and return it to V i j , where LT is the life cycle of the kana; Step 3: V i j Generate the Merkle root Mroot of the identity information by using the Merkle tree structure for the identity attribute information ATTR j ={attr 1 , attr 2 ,…, attr n}, and then construct the verifiable identity credential VC of the vehicle by using Mroot j as the claim of the verifiable credential j ; j ; Step 4: V i j Randomly select an element and calculate E j = e j P and η j = sk j H 4 (PID j ) + e j PH 4 (Mroot j ), then calculate and send {PID j , ATTR j , VC j , pk j , η j , E j} to Issue i for identity credential verification and issuance; Step 5: Issue i First, verify the freshness of the message and verify the equation η by calculation j P = pk j H 4 (PID j ) + E j H 4 (Mroot j ) are equal. If they are equal, it means the message is valid and complete. Then, generate Mroot' through ATTR j and verify whether it is equal to Mroot in the message j ; j whether they are equal; Step 6: If all validations in Step 5 pass, Issue i As a consensus node of the blockchain, add f j = H 2 (PID j , pk j , Mroot j ) to the dynamic accumulator on the blockchain, and encapsulate (PID j , pk j , ACC, upmsg) in the block for network-wide broadcast, where Acc is the accumulated value and upmsg is the auxiliary information. Otherwise, terminate the current session.
4. The cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity according to claim 1, characterized in that in the access credential generation stage of Stage C, the specific implementation is as follows: Step 1: V i j The selective disclosure service provider needs to verify the information, and conceal the identity attribute information ATTR j Generate a sparse Merkle multi-value proof Mproof using a sparse Merkle tree structure j,req , conceal the unnecessary sensitive information, and retain the complete Mroot j Recovery path, and then generate a verifiable access credential VC j,req , which includes Mproof j,req and Mroot j ; Step 2: V i j First, randomly select an element and calculate U j = u j P, then calculate σ j = H 2 (PID j , U j , VC j,req ) and β j = H 3 (M j,req , PID j , TS j , U j ); Step 3: V i j Generate signature information τ j ={U j ,δ j}, where δ j =sk j σ j +u j β j , and then send the service request message {PID j ,M j,req ,TS j ,VC j,req ,τ j} to the edge verification node RSU of the request message i。 5. The cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity according to claim 1, characterized in that in the vehicle cross - domain authentication stage of Stage D, the specific implementation is as follows: Step 1: RSU i First, check the freshness of the service request message, and then verify the equation δ j P = σ j pk j +U j β j to check if they are equal. If they are equal, it indicates that the message is valid and complete. In addition, use the equation for batch verification of messages to improve the verification efficiency of messages; Step 2: If all verifications in step 1 are passed, RSU i Using Sparse Merkle Mproof j,req Restore V i j Merkle root of identity information 'Mroot' j , if the equation Mroot j =Mroot' j Establishment, RSU i Query the dynamic accumulator Mroot j Does it exist? If so, V i j Authentication succeeds, otherwise the current session is terminated.
6. The cross - domain authentication method for the Internet of Vehicles based on blockchain and self - sovereign identity according to claim 1, characterized in that in the vehicle identity revocation stage of Stage E, the specific implementation is as follows: Step 1: KGC i By calculating Restore the real identity of malicious vehicle V i j and terminate the life cycle of V's i j pseudonym; Step 2: KGC i Submit {PID j , R j , LT} to the blockchain, update through the value of the dynamic accumulator, and revoke the identity credential issued by malicious vehicle V i j .
Citation Information
Cited By
Internet of vehicles decentralized cross-domain identity authentication method based on block chain under strict supervision
CN121841730A