V2C post quantum authentication and key agreement method based on RLWE
By adopting the V2C post-quantum authentication and key negotiation method based on RLWE and hashing methods in the Internet of Vehicles environment, combined with fuzzy validator and honey word technology, the problem that the existing technology cannot resist quantum computer attacks and computing communication overhead is solved, and efficient and secure vehicle identity authentication and key negotiation are achieved.
Patent Information
- Application Number
- CN202510345048.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-03-24
AI Technical Summary
The prior art cannot effectively resist the attacks of quantum computers in a post-quantum environment, and the computing and communication overhead in the Internet of Vehicles scenario is high, unable to meet efficient needs, and cannot effectively resist the threat of key leakage.
The V2C post-quantum authentication and key negotiation method designed based on ring fault tolerance learning (RLWE) and hashing methods is adopted, combined with fuzzy validator and honey word technology, to reduce the calculation and communication overhead of the AKA process, resist the attacks of quantum opponents, and realize the confidentiality of the true identity of the legal vehicle.
It effectively reduces the computing and communication overhead of the AKA process, resists attacks from quantum computers, realizes the confidentiality of vehicle identity and the security of keys, and is suitable for efficient vehicle networking environments.
Smart Images

Figure CN120090802A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of vehicle networking information security, and particularly relates to a post-quantum authentication and key negotiation method for V2C based on RLWE. Background Art
[0002] With the rapid development of vehicle networking, vehicles can collect some information on the road, such as weather, speed, traffic conditions, etc. through sensors, radio frequency identification devices and on-vehicle recorders, and exchange information with infrastructure through wireless networks, improving the efficiency of the traffic system. A typical vehicle networking architecture consists of vehicles, on-board units OBU, roadside units RSU, trusted authorities TA, and cloud or fog servers, etc. Under this architecture, there are usually communication methods such as V2V, V2R and V2C to ensure timely communication among various entities in the vehicle and traffic system.
[0003] Although the development of vehicle networking has brought many conveniences, the emergence of some malicious entities may damage the secure communication environment. For example, malicious vehicles may provide false traffic information, leading to serious traffic accidents; other malicious nodes will leak the privacy information of vehicles, resulting in the collapse of the communication system of the vehicle networking system. In addition, with the development of quantum computers, quantum algorithms can break traditional encryption algorithms (such as algorithms based on discrete logarithm and large integer factorization problems). Therefore, how to design a quantum-resistant secure identity authentication protocol in the existing vehicle networking scenario to ensure the confidentiality and integrity of identity data is a key problem to be solved.
[0004] In the current post-quantum environment, lattice-based cryptography occupies an important position in the field of post-quantum cryptography. However, in the existing lattice-based cryptography schemes, they all have large computational and communication overheads, cannot meet the efficient requirements in vehicle networking mobile communication, and cannot resist the threat of key leakage caused by signal functions during the key exchange process.
[0005] Scholars have proposed many schemes to resist the risk of key leakage, but these schemes still show certain deficiencies. Some identity authentication schemes based on identity and smart cards cannot achieve true two-factor security and cannot resist password guessing attacks. Then, some scholars proposed the "fuzzy verifier + honey words" technology, and its wide applicability has been effectively proven. The fuzzy verifier can perform matching verification within a certain fault tolerance range, improving the success rate of verification and user experience. The honey words technology generates some forged "honey words" for real data or accounts. These "honey words" are very similar to the real data. If an attacker uses the honey words for operations, the system can immediately detect and take corresponding measures. Therefore, the "fuzzy verifier + honey words" technology can effectively resist password guessing attacks and the threat of key leakage. However, with the rapid development of quantum computers, these schemes face new challenges and are difficult to provide effective post-quantum security guarantees.
[0006] However, the existing "fuzzy validator + honey words" may face the risk of honey words being cracked. If the honey word generation rule is simple and lacks randomness, attackers may distinguish honey words from real passwords through analysis. They can then avoid the honey word trap and render the honey word defense mechanism ineffective. If the system is a multi-node system, there is a risk of collusion attacks by internal personnel. If honey word information or key data for fuzzy verification is stored and processed on multiple nodes, some internal personnel may collude with attackers to leak honey words or interfere with the fuzzy verification process, bypassing the system's security mechanism. In addition, since the existing technology adds the "fuzzy validator + honey words" part, it may further increase some computing resources. Therefore, a suitable mechanism needs to be designed to balance security and performance. Summary of the Invention
[0007] Objective of the Invention: The objective of the present invention is to address the deficiencies in the existing technology and provide a V2C post-quantum authentication and key agreement method based on RLWE. Designed based on ring learning with errors (RLWE) and hash methods, it can effectively reduce the computational and communication overhead of the AKA process, resist attacks from quantum adversaries, and achieve the confidentiality of the true identities of legitimate vehicles. In addition, the present invention also considers the "fuzzy validator + honey words" technology in the AKA process to address key leakage attacks and ensure the security of keys.
[0008] Technical Solution: A V2C post-quantum authentication and key agreement method based on RLWE of the present invention includes the following steps:
[0009] Step (1), System initialization, select the master key s and the seed σ from the random sample ψ 1 , select a pseudorandom generator to generate the public key pk, and then select the corresponding hash function. The registration authority RA broadcasts the necessary system parameters;
[0010] Step (2), Registration phase, the cloud server CS and the vehicle register with the registration authority RA. The registration authority RA generates the identity CID of the CS j and the private key s of the cloud server j , and then calculate A j to hide the private key s j ; store {s j , h(·), σ 1}, RA generates vehicle-related parameters {C i , B i , h(·), σ 1 , e} and stores them locally in the vehicle;
[0011] Step (3), Login phase, the cloud server CS j selects the secret polynomial s c and the random number sc , calculate relevant security parameters and broadcast {R j , PID j , S j , FS j} to the vehicle, and the vehicle inputs the ID and password and calculates with the local B i for verification. If the verification is successful, the vehicle successfully logs in;
[0012] Step (4), authentication and key negotiation phase: The vehicle checks the timestamp and then selects a random polynomial. After calculating the security parameters, it sends a message to the RA. After the RA verifies the vehicle's identity, it sends the corresponding message to the CS; After the CS verifies the identities of the vehicle and the RA, it calculates the session key SK ij and sends the corresponding message to the vehicle. The vehicle verifies it and calculates the session key SK according to its content ij and verifies;
[0013] Step (5), identity and password update phase: The user inputs the original personal information. After the vehicle successfully verifies, the user inputs the new personal message. The vehicle records the latest data and updates the honeyword list.
[0014] Further, the detailed process of the initialization phase in step (1) is as follows:
[0015] Step (1-1): The registration structure RA selects s as the master key from the sample ψ; Select e ∈ ψ, σ 1 as the seed; Select the pseudorandom generator PRGG(·): then a = G(σ 1 ); pk = a · s + e is the public key;
[0016] Step (1-2): The RA selects a hash function denoted as h i (·);
[0017] where i = 0, 1, 2, 3, l i represents the length of the output of the hash function;
[0018] Step (1-3): The vehicle selects an integer 2 4 ≤ n 0 ≤ 2 8 to be used as a fuzzy verifier to resist offline guessing, and sets m 0 = 20 as the number of honeywords in the honeyword list. The vehicle and the cloud server maintain a Nonce list to cache the random numbers within the current time window;
[0019] Finally, the registration authority RA broadcasts {q, σ 1 , pk, h i(·)} as system parameters.
[0020] Further, the specific process of the registration phase in step (2) is as follows:
[0021] Step (2-1), cloud server CS j Selects a unique identity CID j , and sends the registration information {CID j} to RA;
[0022] Step (2-2), RA generates random numbers k j , n 0 is an integer selected in the initialization phase 2 4 ≤n 0 ≤2 8 ; calculates s j =h(h(CID j ||s||k j ) mod n 0 ), sends {A j , h(·), σ 1 , e} to CS j . Honey_List is the honey word list maintained by CS j , storing {h(CID j ||s), k j , Honey_List = Null}; Honey_List = Null is the honey word list, and CS maintains a honey word list during the registration phase to store the honey words when the vehicle logs in;
[0023] Step (2-3), CS j After receiving {A j , h(·), σ 1}, restores the private key To avoid the private key being sent in plain text directly, CS j stores {s j , h(·), σ 1}, completing the registration of cloud server CS j ; Step (2-4), the user inputs ID and password UID i , PW i , the vehicle selects a random sequence α i , calculates UPW i =h(UID i ||PW i ), for subsequent calculation of security parameters; UID i is the ID of the vehicle user; PW i is the password corresponding to the user ID, and UPW iThe result of hashing the user's ID and password, which is used for the calculation of subsequent security parameters;
[0024] The vehicle will send it to the RA;
[0025] Step (2-5): After receiving the vehicle request message, the RA generates a random sequence k i , calculates the private key s i of the vehicle V i = h(ID i ||s||k i ||h(ID i ||s) mod n 0 ), calculates Sends {A i , h(·), σ 1 , e} to the registered vehicle, and the RA stores {h(ID i ||s), k i , Honey_List = Null} in the ID database T ID ;
[0026] T ID is the ID database list stored by the RA; The vehicle does not directly store the private key s of the vehicle locally i , but stores it in the vehicle's local security module TTP in the form of C i ;
[0027] Step (2-6): The vehicle V i calculates the private key and C i to protect the private key from being stored in plain text;
[0028] V i selects the fuzzy verifier parameter n 0 , calculates B i = h(s i ||ID i ||h(UID i ||PW i ) mod n 0 ); 2 4 ≤ n 0 ≤ 2 8 ;
[0029] V i stores the tuple {C i , B i , h(·), σ 1 , e} in the security module TTP to complete the vehicle registration.
[0030] Furthermore, the specific process of the login phase in step (3) is as follows:
[0031] Step (3-1), CS j Randomly sample s from the sample ψ c and s c , select Nonce n j , use the seed σ 1 to generate the polynomial a, timestamp TS j , then the current freshness is FS j = TS j ||n j , then calculate R j = a·s c +e c , Participate in the subsequent calculation of θ, and θ is used by CS j to verify the identity of RA and ensure that the message M 2 has not been tampered with by a malicious adversary; CS j Calculate the pseudonym Within the expiration time of TS j , CS j Periodically broadcasts {R j , PID j , FS j};
[0032] Here, R j is the calculation result of the RLWE hard problem and is used for RA to calculate in the subsequent authentication and key negotiation process Participate in the subsequent calculation of θ, and θ is used by CS j to verify the identity of RA and ensure that the message M 2 has not been tampered with by a malicious adversary; B i is the data stored in the TTP during the vehicle registration phase;
[0033] Step (3-2), V i After receiving {R j , PID j , FS j}, input the login credentials UID i , ID i , PW i , calculate Subsequently, check whether it is equal to B stored in the vehicle TTP i ; if they are equal, continue, otherwise check SUM<m 0 , if SUM<m 0 , then SUM + 1, Inserted into the honey word list, otherwise terminated. This operation can prevent the threat brought by key mismatch attacks; the present invention sets m 0 = 20 as the maximum capacity of the honey word list, and maintains a counter SUM to record the number of session terminations between the vehicle and the CS, preventing possible key mismatch attacks.
[0034] Further, the specific process of the authentication and key negotiation phase in step (4) is as follows:
[0035] Step (4-1), V i Checks the current freshness FS j = TS j ||n j , where is the time when V i receives the CS j message, checks whether the Nonce n j is sent for the first time. If n j already exists in the Nonce list, the message is rejected;
[0036] If the above conditions are met, select small polynomials s v , e v , s′ v , e′ v , e′ c from the binomial distribution ψ, and generate the polynomial a = G(σ 1 ) according to the seed σ 1 to ensure the security of the temporary secrets s v , e v ,, s′ v , e′ v . Calculate E i = a·s v + e v , E′ i = a·s′ v + e′ v for participating in the subsequent calculation of F i . F i is used by the RA to verify that the message M 1 sent by the vehicle has not been tampered with by an adversary. Calculate c 1 = pk·s′ v + e′ c + Encode(v 1 ), μ 1 = h(v 1 ). μ 1 is an important parameter for calculating the true identity ID i of the vehicle;
[0037] Here, Ei and E' i are both intermediate quantities used in subsequent vehicle calculations. F i is used by RA to verify that the message M sent by the vehicle 1 has not been tampered with by an adversary. c 1 is used to hide the secret polynomial v 1 . μ 1 is an important parameter for RA to calculate the true identity ID of the vehicle i ;
[0038] To ensure the security of the vehicle's true identity, Noncen i is selected, and the freshness FS of the current vehicle is calculated i = TS i ||n i and the pseudonym Then the hash value F i = h(PID i ||s i ||E i ||E' i ||FS i ) is used by RA to verify the identity of vehicle V i , and J i = R j ·s i and A = h(J i ||PID i ||PID j ||FS i ) are used for subsequent identity verification, where J i is an important component of the final session key SK ij ;
[0039] Finally, vehicle V i sends a request message M 1 = {E i , E' i , c 1 , PID i , F i , A, TS i , FS j} through the open channel to RA;
[0040] Step (4-2), after RA receives the request message M 1 , it first checks whether the timestamp TS i meets the requirement n i has been sent for the first time, and recalculates the polynomial a = G(σ 1 ). If it meets the requirement, then the check is calculated If they are not equal, then Fi Insert honeyword list, otherwise check timestamp TS j , Calculate v 1 =Decode(c 1 -E′ i ·s),μ 1 =h(v 1 ), from V i Pseudonym PID i Extract calculate
[0041] Next, RA calculates and For CS j Verification, at the same time, RA calculation and ρ = h(A||CID" j ||CID j ||s i ||E′ i ) for V i Verification of
[0042] Finally, RA sends message M 2 ={E″ i ,PID i ,CID″ j ,θ,ρ,FS i} to CS j ;
[0043] Step (4-3), receiving message M 2 After that, CS j First check the freshness of the current timestamp FS i , calculate the polynomial a=G(σ 1 ), according to E″ i recover Calculate J i =E i ·s c =(a·s i +e i )·s c and A=h(J i ||PID i ||PID j ||FS i ); then CS j verify If verification fails, the CS j Reject message M 2 Otherwise, CS j Select n ij , calculate the current freshness FSij = TS ij || n ij and the session key SK ij = h(J i || PID i || CID j || FS ij ) and the message L for vehicle V i verification j = h(SK ij || CID″ j || ρ || CID j || FS ij ); finally, CS j sends the message M 3 = {L j , CID″ j , ρ, FS ij} to V i ;
[0044] Step (4-4), vehicle V i receives the message M 3 and checks the freshness FS ij , and restores CS j according to CID″ j 's Then verify If they are equal, calculate the session key Finally, verify
[0045] Furthermore, the specific process of the step (5) identity and password update phase is as follows:
[0046] Step (5-1), the user inputs the original personal information {UID i , ID i , PW i}, and then the vehicle calculates B i = h(s i || ID i || h(UID i || PW i ) mod n 0 ), and then checks If they are equal, the user is required to input the information to be updated, otherwise, insert B i into the honeyword list and reject the request;
[0047] Step (5-2), the user inputs the new personal information The vehicle calculates the new
[0048]
[0049] Step (5-3), the vehicle successfully updates the user's identity and password At the same time, the vehicle updates in the TTP and replace B i and C i
[0050] Advantageous effects: The present invention uses lattice-based RLWE hard problems and proposes a post-quantum authentication and key agreement scheme for V2C, which can resist attacks of quantum computers and effectively reduce the threats of offline password guessing attacks and key mismatch attacks. The present invention innovatively uses fuzzy verifiers and honey words technology to achieve perfect forward secrecy and anonymity characteristics, and also has a certain resistance to side-channel attacks, with more reliable security. The present invention has lower computational and communication overheads and is applicable to V2C scenarios with high efficiency requirements. Brief Description of the Drawings
[0051] Figure 1 is the system model diagram of the present invention;
[0052] Figure 2 is the flow chart of authentication and key agreement in the embodiment;
[0053] Figure 3 is the comparison diagram of computational overheads in the embodiment;
[0054] Figure 4 is the comparison diagram of communication overheads in the embodiment. Detailed Description of the Invention
[0055] The technical solution of the present invention will be described in detail below, but the protection scope of the present invention is not limited to the described embodiments.
[0056] Such as Figure 1As shown in the figure, the present invention involves three participating entities, namely, a vehicle, a registration authority RA, and a cloud server CS. Each vehicle is equipped with an on-board unit OBU. It is assumed that the storage and computing capabilities of each vehicle are limited. Before communication, it is necessary to register with the RA through a secure channel. In addition, the vehicle is also deployed with a trusted platform module (TPM) for storing encryption keys and performing encryption operations to ensure the security and integrity of the system. The RA is a highly secure and trusted entity. It is assumed that the RA has sufficient computing power and storage space to generate and distribute the parameters required by the system. All vehicles and CS need to register with the RA to generate a unique long-term session key to ensure the privacy of the vehicle. The RA is controlled by the traffic management department, ensuring reliability and security. The RA is the only entity that can trace the true identity of the vehicle. The CS is an honest but curious entity. The CS is responsible for storing security parameters and performing corresponding encryption and decryption operations. The CS has powerful computing and storage capabilities. Before communication, the CS also needs to register with the RA.
[0057] As Figure 2 shown, the RLWE-based V2C post-quantum authentication and key negotiation method of this embodiment includes the following steps:
[0058] Step (1), System initialization: Select the master key s and the seed σ from the random sample ψ 1 , select a pseudo-random generator to generate the public key pk, and then select the corresponding hash function, and the registration authority RA broadcasts the corresponding system parameters;
[0059] Step (2), Registration phase: The cloud server CS and the vehicle register with the registration authority RA. The registration authority RA generates the identity CID of the CS j and the private key s of the cloud server j , and then calculate A j to hide the private key s j ; Store {s j , h(·), σ 1};
[0060] Step (3), Login phase: The cloud server CS j selects the secret polynomial s c and the random number s c , calculates the relevant security parameters and broadcasts them to the vehicle. The vehicle inputs the ID and password and calculates the data and the local data B i for verification. If the verification is successful, the login is successful;
[0061] Step (4), Authentication and key negotiation phase: After the vehicle checks the timestamp, it selects a random polynomial, calculates the security parameters and sends the message to the RA. After the RA verifies the vehicle's identity, it sends the corresponding message to the CS; After the CS verifies the identities of the vehicle and the RA, it calculates the session key SKij And send the corresponding message to the vehicle, which verifies it and calculates the session key SK according to its content ij And verify;
[0062] Step (5), Identity and Password Update Phase: The user inputs the original personal information. After the vehicle successfully verifies, the user inputs a new personal message, and the vehicle records the latest data and updates the honeyword list.
[0063] The detailed process of step (1), the initialization phase, in this embodiment is as follows:
[0064] Step (1-1): The registration authority RA selects s as the master key from the sample ψ; selects e ∈ ψ, σ 1 as the seed; selects a pseudorandom generator PRGG(·): Then a = G(σ 1 ); pk = a·s + e is the public key;
[0065] Step (1-2): RA selects a hash function Denoted as h i (·);
[0066] Where i = 0, 1, 2, 3, l i Represents the length of the output of the hash function;
[0067] Step (1-3): The vehicle selects an integer 2 4 ≤ n 0 ≤ 2 8 to be used as a fuzzy verifier to resist offline guessing, and sets m 0 = 20 as the number of honeywords in the honeyword list. The vehicle and the cloud server maintain a Nonce list to cache random numbers within the current time window;
[0068] Finally, the registration authority RA broadcasts {q, σ 1 , pk, h i (·)} as the system parameters.
[0069] The specific process of step (2), the registration phase, in this embodiment is as follows:
[0070] Step (2-1): The cloud server CS j selects a unique identity CID j , and sends the registration information {CID j} to RA;
[0071] Step (2-2): RA generates random numbers k j , n 0 is the integer selected in the initialization phase, and 2 4 ≤ n 0 ≤ 2 8; Calculate s j = h(h(CID j ||s||k j ) mod n 0 ), Send {A j , h(·), σ 1 , e} to CS j , where Honey_List is the honey word list maintained by CS j , storing {h(CID j ||s), k j , Honey_List = Null};
[0072] Step (2-3), CS j After receiving {A j , h(·), σ 1}, recover the private key CS j Stores {s j , h(·), σ 1}, completing the registration of cloud server CS j ;
[0073] Step (2-4), the user inputs ID and password UID i , PW i , the vehicle selects a random sequence α i , calculates UPW i = h(UID i ||PW i ), for subsequent calculation of security parameters; here, UID i is the ID of the vehicle user; PW i is the password corresponding to the user ID, and UPW i is the result of hashing the user ID and password;
[0074] Then the vehicle sends to RA;
[0075] Step (2-5), after receiving the vehicle request message, RA generates a random sequence k i , calculates the private key s i of vehicle V i = h(ID i ||s||k i ||h(ID i ||s) mod n 0 ), calculates Send {A i , h(·), σ 1 , e} to the registered vehicle, and RA stores {h(ID i||s),k i , Honey_List = Null} in the ID database T ID ;
[0076] Step (2-6), vehicle V i Calculate the private key and C i to protect the private key from being stored in plain text;
[0077] V i Select the fuzzy verifier parameter n 0 , calculate B i = h(s i ||ID i ||h(UID i ||PW i ) mod n 0 ); 2 4 ≤ n 0 ≤ 2 8 ;
[0078] V i Store the tuple {C i , B i , h(·), σ 1 , e} in the security module TTP to complete vehicle registration.
[0079] The specific process of step (3), the login phase, in this embodiment is as follows:
[0080] Step (3-1), CS j Randomly sample s c and s c from the sample ψ, select Nonce n j , use the seed σ 1 to generate the polynomial a, the timestamp TS j , then the current freshness is FS j = TS j ||n j , then calculate R j = a·s c + e c , Participate in the subsequent calculation of θ, where θ is used by CS j to verify the identity of RA and ensure that the message M 2 has not been tampered with by a malicious adversary; CS j Calculate the pseudonym Within the expiration time of TS j , CS j Periodically broadcast {R j , PIDj , FS j};
[0081] Step (3-2), vehicle V i Upon receiving {R j , PID j , FS j}, input the login credential UID i , ID i , PW i , and calculate Subsequently, check whether it is equal to B stored in vehicle TTP i ; if equal, continue, otherwise check SUM < m 0 , if SUM < m 0 , then SUM + 1, Insert it into the honey word list, otherwise terminate.
[0082] The specific process of the authentication and key negotiation phase in this embodiment, step (4), is as follows:
[0083] Step (4-1), V i Check the current freshness FS j = TS j ||n j , where is the time when V i received the CS j message, check whether the Nonce n j is sent for the first time. If n j already exists in the Nonce list, reject the message;
[0084] If the above conditions are met, select a small polynomial s v , e v , s′ v , e′ v , e′ c , from the binomial distribution ψ, and generate the polynomial a = G(σ 1 ). To ensure the security of the temporary secrets s 1 , e v , s′ v , e′ v , e′ v , calculate E i = a · s v + e v , E′ i = a · s′ v + e′ v , for participating in the subsequent F i , Fi is used by RA to verify the message M sent by the vehicle 1 has not been tampered with by an adversary, and calculate c 1 = pk·s′ v + e′ c + Encode(v 1 ), μ 1 = h(v 1 ), μ 1 is an important parameter used to calculate the true identity ID of the vehicle i ;
[0085] Select Noncen i , and calculate the freshness FS of the current vehicle i = TS i || n i and the pseudonym Then calculate the hash value F i = h(PID i || s i || E i || E′ i || FS i ) for RA to verify the identity of vehicle V i , and calculate J i = R j · s i and a = h(J i || PID i || PID j || FS i ) for subsequent identity verification, where J i is an important part of the final session key SK ij ;
[0086] Finally, vehicle V i sends a request message M to RA through an open channel 1 = {E i , E′ i , c 1 , PID i , F i , A, TS i , FS j};
[0087] Step (4-2), after RA receives the request message M 1 , first check the timestamp TS i to see if it meets n i is the first time it is sent, and calculate the polynomial a = G(σ 1 ), if it meets the requirements, then calculate the check If they are not equal, then insert D i into the honey word list. Otherwise, check the timestamp and calculate v 1 = Decode(c 1 - E′ i · s), μ 1 = h(v 1 ). Extract from V i the kana PID i ; Calculate
[0088] Next, RA calculates and for the verification of CS j ; at the same time, RA calculates and ρ = h(A || CID″ j || CID j || s i || E′ i ) for the verification of V i ;
[0089] Finally, RA sends the message M 2 = {E″ i , PID i , CID″ j , θ, ρ, FS i} to CS j ;
[0090] Step (4 - 3), after receiving the message M 2 , CS j first checks the freshness FS of the current timestamp i , calculates the polynomial a = G(σ 1 ) again, restores according to E″ i and calculates J = E i · s i = (a · s c + e i ) · s i and A = h(J c || PID i || PID i || FS j || FS i ); then CS j verifies If the verification fails, then CS j rejects the message M 2 , otherwise, CS j selects n ij , calculates the current freshness FS ij=TS ij ||n ij and session key SK ij =h(J i ||PID i ||CID j ||FS ij ) and the message L for vehicle V i verification j =h(SK ij ||CID″ j ||ρ||CID j ||FS ij ); finally, cS j sends the message M 3 ={L j ,CID″ j ,ρ,FS ij} to V i ;
[0091] Step (4-4), after vehicle V i receives the message M 3 , checks the freshness FS ij , and restores CS j according to CID″ j of Then verifies If they are equal, calculates the session key Finally, verifies
[0092] The specific process of the identity and password update phase in step (5) of this embodiment is as follows:
[0093] Step (5-1), the user inputs the original personal information {UID i ,ID i ,PW i}, then the vehicle calculates B i =h(s i ||ID i ||h(UID i ||PW i ) mod n 0 ), then checks If they are equal, requests the user to input the information to be updated, otherwise, inserts B i into the honeyword list and rejects the request;
[0094] Step (5-2), the user inputs the new personal information The vehicle calculates the new
[0095]
[0096] Step (5-3), the vehicle successfully updates the user's identity and password At the same time, the vehicle updates in the TTP and replaces B i and C i .
[0097] This embodiment uses the widely accepted cryptographic library NTL to measure the execution time of primitives on the following platform: "CPU architecture: 64-bit, processor: Intel(R) Core(TM) i7-12700@2.10GHz, memory: 32GB, operating system: Windows 11 Professional." The NTL library is a high-performance, portable, and flexible C++ library for performing number theory operations, especially those involving multi-precision arithmetic and polynomial arithmetic. We execute these operations 5000 times to obtain the average time. The results are shown in Table 1.
[0098] Table 1
[0099] Cryptographic operations Overhead (milliseconds) Hash operation AHA3-256 0.0019 <![CDATA[Hash operation {0, 1} * →{0, 1} l > 0.0002 <![CDATA[Hash operation {0, 1} l →R q > 0.0025 <![CDATA[Hash operation R q →χ γ > 0.0070 <![CDATA[R q Execution time of the above two polynomial multiplications (n = 512, q = 12289)]]> 3.5418 <![CDATA[R q Execution time of adding the above two polynomials (n = 512, q = 12289)]]> 0.0852 <![CDATA[R q Execution time of the above two polynomial multiplications (n = 512, q = 7557773)]]> 4.8863 <![CDATA[R q Execution time of the addition of the above two polynomials (n = 512, q = 7557773)]]> 0.0861 <![CDATA[R q Execution time of the above two polynomial multiplications (n = 512, q = 1073479709)]]> 5.0578 <![CDATA[R q Execution time of the addition of the above two polynomials (n = 512, q = 1073479709)]]> 0.0945 <![CDATA[R q Execution time of the Cha(*) function]]> 0.0343 <![CDATA[R q Execution time of the Mod2(*) function in 0.0650 Signature function Sgnl execution time 0.0008
[0100] Compare the actual application calculation overhead of the technical solution of the present invention with that of other solutions. The results are as Figure 3 shown. Whether it is the calculation overhead of the vehicle user side, the cloud server side, or the total calculation overhead, the present invention has obvious advantages. Compare the actual application communication overhead of the technical solution of the present invention with the communication overhead of other solutions. The results are as Figure 4 shown. The total communication overhead of the technical solution of the present invention is the lowest.
[0101] In summary, the present invention solves two main defects of the prior art: one is that it does not consider the threat of quantum computers to existing public key encryption schemes, and the other is that the calculation and communication overheads are relatively high and cannot meet the requirements of low-latency sensitive devices in the vehicle networking environment.
Claims
1. A V2C post-quantum authentication and key agreement method based on RLWE, characterized in that: The following steps are involved: Step (1), system initialization, select the master key s and seed σ1 from the random sample ψ, select the pseudo-random generator to generate the public key pk, then select the corresponding hash function, and the registration authority RA broadcasts the corresponding system parameters; Step (2), during the registration phase, the cloud server CS and the vehicle register with the registration authority RA, which generates the identity CID of CS. j and the private key of the cloud server j , and then calculate A j To hide private keys j ;Storage {s j ,h(·),σ1}; Step (3), login phase, cloud server CS j Choose the secret polynomial s c With random number s c , calculate the relevant security parameters and broadcast them to the vehicle, the vehicle enters the ID and password and calculates the data With local data B i Verify and log in successfully if the verification is successful; Step (4), authentication and key negotiation phase, the vehicle checks the timestamp and selects a random polynomial, calculates the security parameters and sends the message to RA, RA verifies the vehicle identity and sends the corresponding message to CS; CS verifies the identity of the vehicle and RA and calculates the session key SK ij The corresponding message is sent to the vehicle, which verifies it and calculates the session key SK based on its content. ij and verify; Step (5), identity and password update phase, the user enters original personal information, after the vehicle is successfully verified, the user enters new personal information, the vehicle records the latest data and updates the honeyword list.
2. The V2C post-quantum authentication and key agreement method based on RLWE according to claim 1 is characterized in that: The detailed process of the initialization phase of step (1) is as follows: Step (1-1), the registration structure RA selects s from the sample ψ as the primary key; selects e∈ψ, σ1 as the seed; selects the pseudo-random generator PRGG(·): Then a=G(σ1); pk=a·s+e is the public key; Step (1-2), RA selects hash function Denoted as h i (·); where i = 0, 1, 2, 3, l i Indicates the length of the hash function output; Step (1-3), vehicle selection integer 2 4 ≤n0≤2 8 Used as a fuzzy verifier to resist offline guessing, and set m0 = 20 to be the number of honey words in the honey word list. The vehicle and cloud server maintain a Nonce list and cache the random numbers in the current time window; The final registration authority RA broadcasts {q,σ1,pk,h i (·)} as system parameters.
3. The V2C post-quantum authentication and key agreement method based on RLWE according to claim 1 is characterized in that: The specific process of the registration phase in step (2) is as follows: Step (2-1), Cloud Server CS j Select a unique CID j , register the information {CID j }Send to RA; Step (2-2), RA generates a random number k j , n0 is an integer selected in the initialization phase, and 2 4 ≤n0≤2 8 ; Calculate s j =h(h(CID j ||s||k j )mod n0), {A j ,h(·),σ1,e} is sent to CS j , Honey_List is CS j Maintain a list of honey words, storing {h(CID j ||s),k j ,Honey_List=Null}; Step (2-3), CS j Upon receiving {A j ,h(·),σ1}, the private key is recovered CS j Storage j ,h(·),σ1}, complete the cloud server CS j Registration; Step (2-4), user enters ID and password UID i ,PW i , the vehicle selects a random sequence α i , calculate UPW i =h(UID i ||PW i ), used for the subsequent calculation of security parameters; here, UID i PW is the ID of the vehicle user; i is the password corresponding to the user ID, UPW i The hashed result of the user's ID and password; The vehicle will then Send to RA; Step (2-5): After receiving the vehicle request message, RA generates a random sequence k i , calculate vehicle V i Private keys i =h(ID i ||s||k i ||h(ID i ||s)mod n0), calculate {A i ,h(·),σ1,e} is sent to the registered vehicle, and RA stores {j(ID i ||s),k i , Honey_List = Null} in the ID database T ID middle; Step (2-6), vehicle V i Calculate the private key and C i Used to protect private keys from being stored in plain text; V i Select the fuzzy verifier parameter n0 and calculate B i =h(s i ||ID i ||h(UID i ||PW i )mod n0); 2 4 ≤n0≤2 8 ; V i In the security module TTP, the tuple {C i ,B i ,h(·),σ1,e}, completing the vehicle registration.
4. The V2C post-quantum authentication and key agreement method based on RLWE according to claim 1 is characterized in that: The specific process of the login phase in step (3) is as follows: Step (3-1), CS j Randomly sample s from the sample ψ c and c , select Noncen j , using seed σ1 to generate polynomial a, timestamp TS j , then the current freshness is FS j =TS j ||n j Then calculate R j =a·s c +e c , Participate in the subsequent calculation of θ, which is used for CS j Verify the identity of RA and ensure that message M2 has not been tampered with by a malicious adversary; CS j Calculating pseudonyms In TS j Within the expiration time, CS j Periodic broadcast {R j ,PID j ,FS j }; Step (3-2), vehicle V i After receiving {R j , PID j , FS j}, input the login credential UID i , ID i , PW i , calculate Then check whether it is equal to B stored in the vehicle TTP i ; if they are equal, continue, otherwise check SUM < m0, if SUM < m0, then SUM + 1, Insert it into the honeyword list, otherwise terminate.
5. The V2C post-quantum authentication and key agreement method based on RLWE according to claim 1, characterized in that: The specific process of the authentication and key negotiation phase in step (4) is as follows: Step (4-1), V i Check the current freshness FS j =TS j ||n j , in Yes V i CS received j The time of the message, check Nonce n j Is this the first time to send? If nonce list already exists, j , then reject the message; If the above conditions are met, then select a small polynomial s from the binomial distribution ψ v ,e v ,s′ v ,e′ v ,e′ c , based on the seed σ1, the polynomial a=G(σ1) is generated. In order to ensure the temporary secret s v ,e v ,,s′ v , e′ v Security, computing E i =a·s v +e v ,E′ i =a·s′ v +e′ v , used to participate in the subsequent F i Calculation of F i It is used by RA to verify that the message M1 sent by the vehicle has not been tampered by the adversary, and calculates c1 = pk·s′ v +e′ c +Encode(v1), μ1=h(v1), μ1 is used to calculate the real ID of the vehicle i Important parameters of Select Noncen i , calculate the freshness FS of the current vehicle i =TS i ||n i and Kana Then calculate the hash value F i =h(PID i ||s i ||E i ||E′ i ||FS i ) for RA verification vehicle V i The identity of J i =R j ·s i and A=h(J i ||PID i ||PID j ||FS i ) is used for subsequent identity verification, where J i is the final session key SK ij An important part of Finally, the vehicle V i Send a request message M1 to RA through the open channel = {E i ,E′ i ,c1,PID i ,F i ,A,TS i ,FS j }; Step (4-2): After receiving the request message M1, RA first checks the timestamp TS i Is it satisfied? n i Is it the first time to send? Calculate the polynomial a=G(σ1) again. If it is satisfied, calculate the check If they are not equal, then F i Insert honeyword list, otherwise check timestamp TS j , Calculate v1 = Decode(c1-E′ i ·s), μ1=h(v1), from V i Pseudonym PID i Extract calculate Next, RA calculates and For CS j Verification, at the same time, RA calculation and ρ = h(A||CID" j ||CID j ||s i ||E′ i ) for V i Verification of Finally, RA sends a message M2 = {E″ i ,PID i ,CID″ j ,θ,ρ,FS i } to CS j ; Step (4-3), after receiving message M2, CS j First check the freshness S of the current timestamp i , calculate the polynomial a=G(σ1) again, according to E″ i recover Calculate J i =E i ·s c =(a·s i +e i )·s c and A=h(J i ||PID i ||PID j ||FS i ); then CS j verify If verification fails, the CS j Reject message M2, otherwise, CS j Select n ij , calculate the current freshness FS ij =TS ij ||n ij and session key SK ij =h(J i ||PID i ||CID j ||FS ij ) and for vehicles V i Verified message L j =h(SK ij ||CID″ j ||ρ||CID j ||FS ij ); Finally, CS j The message M3 = {L j ,CID″ j ,ρ,FS ij }Send to V i ; Step (4-4), vehicle V i After receiving message M3, check the freshness FS ij , according to CID″ j Recover from CS j of Then verify If they are equal, the session key is calculated Finally, verify 6. The V2C post-quantum authentication and key agreement method based on RLWE according to claim 1, characterized in that: The specific process of the identity and password update phase in step (5) is as follows: Step (5-1), user enters original personal information {UID i ,ID i ,PW i }, then the vehicle calculates B i =h(s i ||ID i ||h(UID i ||PW i )modn0), then check If they are equal, the user is asked to enter the information to be updated. Otherwise, i Insert the honeyword list and deny the request; Step (5-2), user enters new personal information Vehicle calculation new Step (5-3), the vehicle successfully updates the user's identity and password At the same time, the vehicle is updated in TTP and Replace B i and C i .
Citation Information
Patent Citations
Password file leakage detection method based on zero factor graph sequence
CN113411339A
Authentication key negotiation method with anti-key exposure characteristic in Internet of Vehicles environment
CN113630243A
Automatic driving vehicle network authentication and key agreement method based on chaotic mapping
CN114205091A
Internet of vehicles efficient batch authentication key negotiation method based on signature
CN117098128A
Unmanned system two-factor authentication and security control method based on cloud network end architecture
CN117201105A