A Blockchain-Enhanced Closed-Loop Authentication Method for Vehicular Ad Hoc Networks
Through the blockchain-enhanced internal closed-loop authentication method of the Internet of Vehicles, the captain's vehicle is dynamically elected, a hierarchical authentication mechanism is built, and the PBFT consensus algorithm and homomorphic encryption technology are used to solve the problems of low efficiency of vehicle networking and high risk of data leakage in the Internet of Vehicles, achieving efficient and secure vehicle authentication and data transmission.
Patent Information
- Application Number
- CN202510579007.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-05-07
AI Technical Summary
There are problems in the Internet of Vehicles, such as low efficiency in vehicle networking and high risk of data leakage. Especially in the absence of roadside infrastructure, it is difficult for the existing technology to effectively ensure safe certification and data transmission between vehicles.
The internal closed-loop authentication method of the Internet of Vehicles is adopted to dynamically elect the captain's vehicle, a hierarchical authentication mechanism is built, and a reverse order traversal of the certified queue verification strategy is used, and a PBFT consensus algorithm and homomorphic encryption technology is combined to generate session identifiers and vehicle signatures to ensure the immutability and reliability of the authentication information.
Significantly reduce certification calculation overhead, improve vehicle networking efficiency, prevent data leakage, ensure the authenticity and integrity of certification information, provide a high-security certification foundation, and enhance the stability and reliability of the vehicle networking system.
Smart Images

Figure CN120110794B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a blockchain-enhanced in-vehicle network internal closed-loop authentication method, belonging to the technical field of in-vehicle network security authentication protocols. Background Art
[0002] As a product of the deep integration of the automotive industry and the Internet of Things, in-vehicle network technology has achieved remarkable development achievements in recent years. By integrating advanced communication technologies, sensor technologies, and data processing technologies, this technology not only greatly improves the safety of road driving but also significantly enhances the data interaction ability between vehicles. For example, vehicles can share key data such as driving status, road conditions, and emergency braking warnings in real time through in-vehicle network technology, thus effectively avoiding traffic accidents. In addition, in-vehicle network technology also greatly optimizes the driving experience of users through intelligent and personalized services such as automatic navigation and remote vehicle control. These technological innovations jointly promote the development of the automotive industry towards a more intelligent and connected direction.
[0003] Despite the many conveniences and advantages brought by in-vehicle network technology, it also faces security challenges that cannot be ignored. In the in-vehicle network environment, due to the need for a large amount of data interaction between vehicles and third-party platforms, there are potential risks of malicious vehicle attacks or privacy leakage by third-party platforms. These risks may not only pose a serious threat to the privacy and security of users but also have an adverse impact on the overall stability and reliability of the in-vehicle network system. More critically, many current in-vehicle network networking methods highly rely on roadside infrastructure and third-party storage platforms, and this dependence undoubtedly increases the risk of privacy leakage. Once these infrastructures or platforms are attacked or malfunction, it may lead to the leakage of a large amount of sensitive information, thus triggering serious security problems. Summary of the Invention
[0004] The purpose of the present invention is to provide a blockchain-enhanced in-vehicle network internal closed-loop authentication method, which performs vehicle security networking aggregation authentication without roadside infrastructure to solve the problems of low vehicle networking efficiency and high data leakage risk existing in the prior art.
[0005] To solve the above technical problems, the present invention is implemented by adopting the following technical solutions:
[0006] The present invention provides a blockchain-enhanced in-vehicle network internal closed-loop authentication method. In the in-vehicle network, any vehicle is selected as the captain vehicle from the vehicle set with common teaming requirements. The authentication method includes:
[0007] If itself is not the captain vehicle, its own authentication status is to be authenticated, and it receives the first authentication request broadcast by the captain vehicle, traverse the authenticated vehicle queue in reverse order, and receive and verify the second authentication request sent by the authenticated vehicle:
[0008] If the verification of the second authentication request fails, delete the corresponding authenticated vehicle from the authenticated vehicle queue that fails the verification;
[0009] If the verification of the second authentication request passes, change its own authentication status to authenticated, sequentially join the authenticated vehicle queue, aggregate its own second authentication request and the verified second authentication request into its own new second authentication request, and broadcast its own new second authentication request to the vehicles to be authenticated; among them, the first authentication request is used to inform the vehicles to be authenticated to receive and judge the second authentication request sent by the authenticated vehicles, and the second authentication request includes a session identifier, vehicle authentication information, vehicle speed, and vehicle signature;
[0010] If it is the team leader vehicle, for the first authentication request broadcast to the vehicles to be authenticated, if the authentication status of all other vehicles in the vehicles with common teaming requirements is authenticated, receive and verify the second authentication request of the last vehicle in the authenticated vehicle queue. If the verification of the second authentication request passes, use the PBFT consensus algorithm to submit the verified second authentication request to the blockchain network.
[0011] Further, the second authentication request includes a generated session identifier; the process of generating the session identifier includes:
[0012] Send a registration request to the vehicle cloud, and receive the private key and unique vehicle identification code feedback by the vehicle cloud;
[0013] In response to receiving the teaming application broadcast by the team leader vehicle, send a unified verification code to the vehicle cloud;
[0014] Receive the unique team identification code assigned by the vehicle cloud;
[0015] Generate a session identifier according to the current timestamp, unique vehicle identification code, and unique team identification code.
[0016] Further, the second authentication request includes generated vehicle authentication information; the process of generating the vehicle authentication information includes:
[0017] Obtain the vehicle speed, the private key feedback by the vehicle cloud, and the generated session identifier and perform homomorphic encryption;
[0018] Randomly select two large prime numbers that satisfy the mathematical properties of homomorphic encryption, and multiply them to obtain the homomorphic encryption modulus ;
[0019] From the multiplicative group of the homomorphic encryption modulus select a random number as the first random number generated during the homomorphic encryption process , and generate an encryption key pair and the second random number generated during the homomorphic encryption process ;
[0020] According to the cyclic group of prime order of the Internet of Vehicles and the generator and the second random number generated during the homomorphic encryption process , according to the formula generate the third random number generated during the homomorphic encryption process ;
[0021] Use the hash function to combine the vehicle speed, the private key fed back by the vehicle cloud, and the generated session identifier with the encryption key pair and the third random number generated during the homomorphic encryption process to generate combined information;
[0022] Use the homomorphic encryption operation to encrypt the combined information with the encryption key pair and the second random number generated during the homomorphic encryption process to generate vehicle authentication information.
[0023] Furthermore, the combined information is expressed as:
[0024] ;
[0025] In the formula, represents the combined information of the th vehicle to be authenticated, represents the hash function, represents the unique team identification code of the th team, represents the current timestamp of the th vehicle to be authenticated in the th team, represents the homomorphic encryption modulus of the th vehicle to be authenticated, represents the first random number generated during the homomorphic encryption process of the th vehicle to be authenticated, represents the vehicle speed of the th vehicle to be authenticated, represents the private key fed back by the vehicle cloud received by the th vehicle to be authenticated, represents the third random number generated during the homomorphic encryption process of the th vehicle to be authenticated, represents the unique vehicle identification code of the th vehicle to be authenticated in the th team.
[0026] Furthermore, the vehicle authentication information is expressed as:
[0027] ;
[0028] In the formula, E [ i , i ] represents the vehicle authentication information of the th vehicle to be authenticated, Enc < N i , B i > r i [ L i ] represents the th vehicle to be authenticated using the encryption key pair < N i ,B i > and the second random number generated during the homomorphic encryption process to encrypt the combined information .
[0029] Furthermore, the second authentication request includes the generated vehicle signature, and the generation process of the vehicle signature includes:
[0030] Obtain the vehicle speed, the private key fed back by the vehicle cloud, the encryption key pair, the generated session identifier, the generated vehicle authentication information, and the third random number generated during the homomorphic encryption process, and use a hash function to combine them to generate the vehicle signature;
[0031] wherein, the vehicle signature is expressed as:
[0032] Sg i = h ( TC v || SP i || t v i || ID v i || N i || B i || E [ i , i ] || R i ) ;
[0033] In the formula, represents the th vehicle signature of the vehicle to be authenticated.
[0034] Furthermore, the second authentication request further includes the vehicle speed, the encryption key pair, and the third random number generated during the homomorphic encryption process, and the second authentication request is expressed as:
[0035] Invite i =< TC v || SP i || Sg i || t v i || ID v i || N i || B i || E [ i , i ] || R i > ;
[0036] In the formula, represents the th second authentication request of the vehicle to be authenticated.
[0037] Furthermore, the new second authentication request of itself is expressed as:
[0038] Invite i '' =< TC v || SP x || t v x || ID v x || N x || B x || E [ x , i ] || R x || Sg x > x ∈ [ 1 , i ]
[0039] In the formula, represents the th new second authentication request of the vehicle to be authenticated itself, represents the The vehicle speed of an authenticated vehicle, Indicating the th vehicle in the th convoy, the current timestamp of the th authenticated vehicle, Indicating the th convoy, the session identifier generated by the th authenticated vehicle, Indicating the homomorphic encryption modulus of the th authenticated vehicle, Indicating the first random number generated during the homomorphic encryption process of the E [ x , i ] Indicating the th authenticated vehicle, the aggregated information of the vehicle authentication information of the th authenticated vehicle to the vehicle authentication information of the th authenticated vehicle, Indicating the third random number generated during the homomorphic encryption process of the th authenticated vehicle, Indicating the vehicle signature generated by the
[0040] Furthermore, the process of receiving and verifying the second authentication request of the last vehicle in the authenticated vehicle queue is expressed as:
[0041] ;
[0042] In the formula, Indicating that the authentication request is correct, Indicating that the authentication request is incorrect, Indicating the first aggregated information verification formula , Indicating the second aggregated information verification formula , Indicating the third aggregated information verification formula , E [ 1 ,i ] Indicating the aggregated information of the vehicle authentication information of the first authenticated vehicle to the th authenticated vehicle, And Respectively represent "if" and "otherwise" in the conditional judgment statement.
[0043] Furthermore, using the PBFT consensus algorithm to submit the verified second authentication request to the blockchain network includes:
[0044] Setting the leader vehicle as the primary node and the remaining vehicles as participating nodes;
[0045] The client initiates an authentication request to the master node. The master node receives the authentication request and generates a pre-prepared message containing the authentication request, which is broadcast to all participating nodes.
[0046] The participating nodes receive and verify the pre-prepared message:
[0047] If the verification passes, the participating nodes store the pre-prepared message and broadcast a prepared message to indicate that they are ready to verify the pre-prepared message.
[0048] The master node and the participating nodes listen for prepared messages from other nodes. If the master node receives prepared messages from more than a preset threshold number of participating nodes, it generates and submits a commit message to all participating nodes to indicate that the pre-prepared message can be verified.
[0049] The participating nodes receive and verify the commit message:
[0050] If the verification passes and it is confirmed that the commit messages received from more than a preset threshold number of participating nodes are legal, the request operation is executed.
[0051] After the request operation is completed, the participating nodes that have executed the request operation generate a response message, which is forwarded to the client through the master node to confirm that the authentication request has been successfully processed.
[0052] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:
[0053] 1. The present invention dynamically elects the captain vehicle and constructs a hierarchical authentication mechanism. The authentication process adopts a verification strategy of traversing the authenticated queue in reverse order, ensuring that only the nodes that fail the verification need to be excluded, avoiding repeated verification of the authenticated vehicles, and significantly reducing the authentication calculation overhead. At the same time, the blockchain commit mechanism based on the PBFT consensus algorithm effectively resists single-point failures and malicious tampering, ensuring the immutability and final consistency of the authentication data, providing a highly secure authentication foundation for the vehicle network, and solving the problems of low vehicle networking efficiency and high data leakage risk existing in the prior art.
[0054] 2. The present invention registers the vehicle through the vehicle cloud and generates a private key and a unique vehicle identification code, ensuring the uniqueness and traceability of each vehicle's identity. At the same time, the present invention assigns a unique team identification code to the members of the same fleet through the vehicle cloud, ensuring the identity consistency of the vehicles within the fleet, the convenience of the authentication process, and generating a session identifier based on the timestamp, vehicle identification code, and team identification code, effectively preventing information tampering and forgery during the authentication process and improving the security of the fleet. At the same time, the vehicle authentication information is encrypted and signed using homomorphic encryption technology and hash functions, not only protecting the privacy information of the vehicle but also ensuring the authenticity and integrity of the authentication information, providing a solid technical guarantee for the efficient and secure operation of the fleet.
[0055] 3. The present invention uses the PBFT consensus algorithm to submit the aggregated authentication requests to the blockchain network, further enhancing the credibility and immutability of authentication. By setting the role division of the primary node and participating nodes, as well as the interaction process of pre-prepare messages, prepare messages, and commit messages, it ensures the reliable dissemination and verification of authentication requests in the blockchain network. Even in the presence of network latency or attacks by malicious nodes, the fault-tolerance mechanism of the PBFT consensus algorithm can guarantee the successful processing and confirmation of authentication requests. This process not only improves the efficiency and reliability of authentication but also provides strong technical support for the long-term stable operation of the vehicle networking system. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 is a schematic flowchart of the blockchain-enhanced in-vehicle network internal closed-loop authentication method provided by an embodiment of the present invention;
[0057] Figure 2 is a schematic structural diagram of the in-vehicle network internal system provided by an embodiment of the present invention;
[0058] Figure 3 is a schematic diagram of the vehicle authentication process provided by an embodiment of the present invention;
[0059] Figure 4 is a schematic diagram of the vehicle authentication timing diagram provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific features in the embodiments of the present invention are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. Without conflict, the technical features in the embodiments of the present invention and the embodiments can be combined with each other.
[0061] Embodiment 1
[0062] As Figure 1 and Figure 3 described, this embodiment introduces a blockchain-enhanced in-vehicle network internal closed-loop authentication method, including:
[0063] In the vehicle networking, any vehicle is selected as the leader vehicle from the set of vehicles with common teaming requirements.
[0064] In the vehicle networking environment, the same driving intention of vehicles means they have similarities in aspects such as driving direction and speed range, facilitating unified management and authentication operations. By selecting the leader vehicle, the present invention clarifies the initiator of the authentication process, making the authentication process organized and coordinated, facilitating the grouped management of vehicles with common teaming requirements, and improving the efficiency and accuracy of authentication.
[0065] If it is not the captain vehicle itself, its authentication status is pending authentication, and it receives the first authentication request broadcast by the captain vehicle, traverse the authenticated vehicle queue in reverse order, and receive and verify the second authentication request sent by the authenticated vehicle:
[0066] After receiving the first authentication request from the captain vehicle, the non-captain vehicle needs to verify the vehicle authentication information of the authenticated vehicle to ensure the authenticity and reliability of the authentication. By traversing the authenticated vehicle queue in reverse order, the present invention can quickly discover authentication problems, ensure that the non-captain vehicle can obtain effective authentication information during the authentication process, avoid false authentication, and gradually establish a trustworthy authentication chain by verifying the requests of the authenticated vehicles.
[0067] If the verification of the second authentication request fails, delete the corresponding authenticated vehicle from the authenticated vehicle queue; when the verification of the second authentication request of the authenticated vehicle fails, it indicates that there may be problems with the authentication information of this vehicle. To ensure the reliability of the authentication chain, the present invention removes it from the authenticated vehicle queue to maintain the accuracy and credibility of the authenticated vehicle queue and prevent invalid or false authentication information from affecting the entire authentication process.
[0068] If the verification of the second authentication request passes, change its own authentication status to authenticated, sequentially join the authenticated vehicle queue, aggregate its own second authentication request and the verified second authentication request into its own new second authentication request, and broadcast its own new second authentication request to the vehicles pending authentication; among them, the first authentication request is used to inform the vehicles pending authentication to receive and judge the second authentication request sent by the authenticated vehicle, and the second authentication request includes a session identifier, vehicle authentication information, vehicle speed, and vehicle signature.
[0069] When the non-captain vehicle successfully verifies the request of the authenticated vehicle, it indicates that it has also passed a part of the authentication process. Therefore, change its own authentication status to authenticated. Sequentially joining the authenticated vehicle queue is to maintain the order of the authenticated vehicles, which is convenient for subsequent management and authentication operations. By aggregating its own second authentication request and the verified second authentication request to form a new second authentication request and broadcasting it, the present invention can transmit the authentication information to more vehicles pending authentication, expand the authentication scope, enable the non-captain vehicle to successfully complete the authentication process, and participate in the dissemination of authentication information. By broadcasting the new second authentication request, the authentication process within the entire vehicle network is accelerated.
[0070] If it is the captain vehicle itself, for the first authentication request broadcast to the vehicles pending authentication, if the authentication status of all other vehicles in the vehicle concentration with the co-teaming requirement is authenticated, receive and verify the second authentication request of the last vehicle in the authenticated vehicle queue. If the verification of the second authentication request passes, submit the verified second authentication request to the blockchain network using the PBFT consensus algorithm.
[0071] The captain vehicle is responsible for initiating the first authentication request and coordinating the entire authentication process. After all other vehicles have completed authentication, the captain vehicle verifies the second authentication request of the last vehicle to ensure the integrity of the entire authentication chain.
[0072] The PBFT (Practical Byzantine Fault Tolerance) consensus algorithm is an algorithm for achieving consistency in a distributed system. Through the verification and consensus of multiple nodes, it ensures the authenticity and reliability of the information submitted to the blockchain network. The present invention guarantees the integrity and accuracy of the authentication process, ensures that all vehicles with co-teaming requirements have completed authentication, and at the same time utilizes the immutable and distributed characteristics of the blockchain to securely store the authentication information in the blockchain network, improving the credibility and traceability of the authentication information.
[0073] Embodiment 2
[0074] Based on the same inventive concept as Embodiment 1, as Figure 2 described, this embodiment introduces the implementation steps of a blockchain-enhanced in-vehicle network internal closed-loop authentication method, including:
[0075] Step 1: In the in-vehicle network, select any vehicle from the set of vehicles with co-teaming requirements as the captain vehicle.
[0076] Step 2: Determine whether itself is the captain vehicle:
[0077] Step 2.1: If itself is not the captain vehicle, its authentication status is pending authentication, and it receives the first authentication request broadcast by the captain vehicle.
[0078] Step 2.1.1: Traverse the queue of authenticated vehicles in reverse order, receive and verify the second authentication request sent by the authenticated vehicles:
[0079] If the verification of the second authentication request fails, delete the corresponding authenticated vehicle from the queue of authenticated vehicles.
[0080] If the verification of the second authentication request passes, change its own authentication status to authenticated, sequentially join the queue of authenticated vehicles, aggregate its own second authentication request and the verified second authentication request into its own new second authentication request, and broadcast its own new second authentication request to the vehicles pending authentication.
[0081] Among them, the first authentication request is used to inform the vehicles pending authentication to receive and judge the second authentication request sent by the authenticated vehicles.
[0082] In this embodiment, the second authentication request includes a generated session identifier; the process of generating the session identifier includes:
[0083] Send a registration request to the vehicle cloud and receive the private key and the unique vehicle identification code feedback by the vehicle cloud;
[0084] In response to receiving the teaming application broadcast by the team leader vehicle, send a unified verification code to the vehicle cloud;
[0085] Receive the unique team identification code assigned by the vehicle cloud;
[0086] Generate a session identifier according to the current timestamp, the unique vehicle identification code and the unique team identification code.
[0087] In this embodiment, the second authentication request includes the generated vehicle authentication information; the process of generating the vehicle authentication information includes:
[0088] Obtain the vehicle speed, the private key feedback by the vehicle cloud, and the generated session identifier and perform homomorphic encryption;
[0089] Randomly select two large prime numbers that satisfy the mathematical properties of homomorphic encryption and multiply them to obtain the homomorphic encryption modulus ;
[0090] From the multiplicative group of the homomorphic encryption modulus select a random number as the first random number generated during the homomorphic encryption process , generate an encryption key pair and the second random number generated during the homomorphic encryption process ;
[0091] According to the generator of the cyclic group of the prime order of the vehicle networking and the second random number generated during the homomorphic encryption process , according to the formula generate the third random number generated during the homomorphic encryption process ;
[0092] Use the hash function to combine the encryption key pair and the third random number generated during the homomorphic encryption process with the vehicle speed, the private key feedback by the vehicle cloud, and the generated session identifier to generate combined information;
[0093] In this embodiment, the combined information is expressed as:
[0094] ;
[0095] In the formula, represents the combined information of the th vehicle to be authenticated, represents the hash function, represents the The unique team identification code of a fleet indicating the th fleet and the current timestamp of the th vehicle to be authenticated, the homomorphic encryption modulus of the th vehicle to be authenticated, the first random number generated during the homomorphic encryption process of the th vehicle to be authenticated, the vehicle speed of the th vehicle to be authenticated, the private key received by the th vehicle to be authenticated from the vehicle cloud feedback, the third random number generated during the homomorphic encryption process of the th vehicle to be authenticated, indicating the unique vehicle identification code of the
[0096] Using homomorphic encryption operations, encrypt the combined information with the encryption key pair and the second random number generated during the homomorphic encryption process to generate vehicle authentication information;
[0097] In this embodiment, the vehicle authentication information is expressed as:
[0098] ;
[0099] In the formula, E [ i , i ] indicating the vehicle authentication information of the Enc < N i , B i > r i [ L i ] th vehicle to be authenticated, indicating that the th vehicle to be authenticated uses the encryption key pair and the second random number generated during the homomorphic encryption process to encrypt the combined information
[0100] In this embodiment, the second authentication request includes the generated vehicle signature, and the generation process of the vehicle signature includes:
[0101] Obtain the vehicle speed, the private key received from the vehicle cloud feedback, the encryption key pair, the generated session identifier, the generated vehicle authentication information, and the third random number generated during the homomorphic encryption process, and use a hash function to combine them to generate a vehicle signature;
[0102] In this embodiment, the vehicle signature is expressed as:
[0103] Sg i = h ( TC v || SP i || t v i || ID v i || N i || B i || E [ i , i ] || R i ) ;
[0104] Wherein, represents the vehicle signature of the th vehicle to be authenticated.
[0105] In this embodiment, the second authentication request further includes the vehicle speed, the encryption key pair, and the third random number generated during the homomorphic encryption process.
[0106] In this embodiment, the second authentication request is expressed as:
[0107] Invite i =< TC v || SP i || Sg i || t v i || ID v i || N i || B i || E [ i , i ] || R i > ;
[0108] Wherein, represents the second authentication request of the th vehicle to be authenticated.
[0109] In this embodiment, the new second authentication request of itself is expressed as:
[0110] Invite i '' =< TC v || SP x || t v x || ID v x || N x || B x || E [ x , i ] || R x || Sg x > x ∈ [ 1 , i ] ;
[0111] Wherein, represents the new second authentication request of the th vehicle to be authenticated itself, represents the vehicle speed of the th authenticated vehicle, represents the current timestamp of the th authenticated vehicle in the th convoy, represents the session identifier generated by the th authenticated vehicle in the th convoy, represents the homomorphic encryption modulus of the th authenticated vehicle, represents the first random number generated during the homomorphic encryption process of the th authenticated vehicle, E [ x , i ] represents the aggregated information of the vehicle authentication information of the th authenticated vehicle to the vehicle authentication information of the th authenticated vehicle, represents the third random number generated during the homomorphic encryption process of the th authenticated vehicle, represents the vehicle signature generated by the th authenticated vehicle.
[0112] Step 2.2: If it is the captain vehicle, broadcast the first authentication request to the vehicle to be authenticated. If the authentication status of all other vehicles in the vehicle set with the co-teaming requirement is authenticated, receive and verify the second authentication request of the last vehicle in the authenticated vehicle queue. If the second authentication request passes the verification, use the PBFT consensus algorithm to submit the verified second authentication request to the blockchain network.
[0113] In this embodiment, the process of the captain vehicle receiving and verifying the aggregated authentication request of the last vehicle is expressed as:
[0114] ;
[0115] In the formula, indicates that the authentication request is correct, indicates that the authentication request is incorrect, indicates the first aggregated information verification formula , indicates the second aggregated information verification formula , indicates the third aggregated information verification formula , and respectively represent "if" and "otherwise" in the conditional judgment statement.
[0116] In this embodiment, the process of receiving and verifying the second authentication request of the last vehicle in the authenticated vehicle queue is expressed as:
[0117] ;
[0118] In the formula, indicates that the authentication request is correct, indicates that the authentication request is incorrect, indicates the first aggregated information verification formula , indicates the second aggregated information verification formula , indicates the third aggregated information verification formula , represents the aggregated information from the authentication information of the 1st authenticated vehicle to the authentication information of the th authenticated vehicle, and respectively represent "if" and "otherwise" in the conditional judgment statement.
[0119] In this embodiment, the vehicle authentication process timing is as Figure 4 described, including:
[0120] In some embodiments, submitting the aggregated authentication request to the blockchain network through the PBFT consensus algorithm includes:
[0121] Set the team leader vehicle as the main node, and the remaining vehicles as participating nodes;
[0122] Use the client to initiate an authentication request to the main node. The main node receives the authentication request and generates a pre-prepared message containing the authentication request, which is broadcast to all participating nodes;
[0123] The participating nodes receive and verify the pre-prepared message:
[0124] If the verification passes, the participating nodes store the pre-prepared message and broadcast a prepared message to indicate that they are ready to verify the pre-prepared message;
[0125] The main node and the participating nodes listen for prepared messages from other nodes. If the main node receives prepared messages from more than 2 / 3 of the participating nodes, it generates and submits a commit message to all participating nodes to indicate that the pre-prepared message can be verified;
[0126] The participating nodes receive and verify the commit message:
[0127] If the verification passes and it is confirmed that the commit messages received from more than 2 / 3 of the participating nodes are legal, then execute the request operation;
[0128] After the request operation is executed, the participating nodes that have executed the request operation generate a response message, which is forwarded to the client through the main node to confirm that the authentication request has been successfully processed.
[0129] Embodiment 3
[0130] Based on the same inventive concept as other embodiments, this embodiment introduces a computer-readable storage medium on which computer instructions are stored. When the computer instructions are executed by a processor, the steps of the method in Embodiment 1 or 2 above are implemented.
[0131] Embodiment 4
[0132] Based on the same inventive concept as other embodiments, this embodiment introduces a computer program product including computer instructions. When the computer instructions are executed by a processor, the steps of the method in Embodiment 1 or 2 above are implemented.
[0133] In summary, in the above embodiments, the present invention dynamically elects a captain vehicle and constructs a hierarchical authentication mechanism. The authentication process adopts a verification strategy of traversing the authenticated queue in reverse order, ensuring that only the nodes that fail the verification need to be removed, avoiding repeated verification of authenticated vehicles, and significantly reducing the authentication calculation overhead. At the same time, the blockchain submission mechanism based on the PBFT consensus algorithm effectively resists single-point failures and malicious tampering, ensuring the immutability and final consistency of the authentication data, providing a highly secure authentication basis for the vehicle network, and solving the problems of low vehicle networking efficiency and high data leakage risk existing in the prior art.
[0134] The present invention registers vehicles through a vehicle cloud, generates private keys and unique vehicle identification codes, ensuring the uniqueness and traceability of each vehicle's identity. At the same time, the present invention assigns unique team identification codes to the members of the same fleet through the vehicle cloud, ensuring the identity consistency of the vehicles within the fleet, the convenience of the authentication process, and generating session identifiers based on timestamps, vehicle identification codes, and team identification codes, effectively preventing information tampering and forgery during the authentication process and improving the security of the fleet. At the same time, homomorphic encryption technology and hash functions are used to encrypt and sign vehicle authentication information, not only protecting the privacy information of the vehicles, but also ensuring the authenticity and integrity of the authentication information, providing a solid technical guarantee for the efficient and secure operation of the fleet.
[0135] The present invention uses the PBFT consensus algorithm to submit aggregated authentication requests to the blockchain network, further enhancing the credibility and immutability of the authentication. It also ensures the reliable propagation and verification of authentication requests in the blockchain network by setting the role division of the primary node and participating nodes, as well as the interaction process of pre-prepare messages, prepare messages, and commit messages. Even in the presence of network delays or attacks by malicious nodes, the fault tolerance mechanism of the PBFT consensus algorithm can ensure the successful processing and confirmation of authentication requests. This process not only improves the efficiency and reliability of the authentication, but also provides strong technical support for the long-term stable operation of the vehicle network system.
[0136] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0137] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general purpose computers, special purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0138] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0139] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0140] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the present invention and the claims. These all fall within the protection scope of the present invention.
Claims
1. A blockchain-enhanced in-vehicle network internal closed-loop authentication method, characterized in that, In the vehicle networking, select any vehicle from the vehicles with co-driving team requirements as the captain vehicle. The authentication method includes: If the vehicle itself is not the captain vehicle, its authentication status is pending authentication, and it receives the first authentication request broadcast by the captain vehicle, traverse the authenticated vehicle queue in reverse order, and receive and verify the second authentication request sent by the authenticated vehicle: If the verification of the second authentication request fails, delete the corresponding authenticated vehicle from the authenticated vehicle queue; If the verification of the second authentication request passes, change the vehicle's own authentication status to authenticated, sequentially join the authenticated vehicle queue, aggregate its own second authentication request and the verified second authentication request into its own new second authentication request, and broadcast its own new second authentication request to the pending authentication vehicles; wherein, the first authentication request is used to inform the pending authentication vehicles to receive and judge the second authentication request sent by the authenticated vehicles; If the vehicle itself is the captain vehicle, broadcast the first authentication request to the pending authentication vehicles. If the authentication status of other vehicles in the co-driving team requirement vehicle set is all authenticated, receive and verify the second authentication request of the last vehicle in the authenticated vehicle queue. If the verification of the second authentication request passes, use the PBFT consensus algorithm to submit the verified second authentication request to the blockchain network; The above-mentioned new second authentication request of the vehicle itself is expressed as: ; Wherein, represents the new second authentication request of the th vehicle to be authenticated itself, represents the vehicle speed of the th authenticated vehicle, represents the current timestamp of the th authenticated vehicle in the th fleet, represents the session identifier generated by the th authenticated vehicle in the th fleet, represents the homomorphic encryption modulus of the th authenticated vehicle, represents the first random number generated during the homomorphic encryption process of the th authenticated vehicle, represents the aggregation information of the vehicle authentication information of the th authenticated vehicle to the vehicle authentication information of the th authenticated vehicle, represents the third random number generated during the homomorphic encryption process of the th authenticated vehicle, represents the vehicle signature generated by the th authenticated vehicle; The process of receiving and verifying the second authentication request of the last vehicle in the authenticated vehicle queue is expressed as: ; In the formula, indicates that the authentication request is correct, indicates that the authentication request is incorrect, indicates the first aggregated information verification formula , indicates the second aggregated information verification formula , indicates the third aggregated information verification formula , indicates the aggregated information from the vehicle authentication information of the first authenticated vehicle to the vehicle authentication information of the th authenticated vehicle, and respectively represent "if" and "else" in the conditional judgment statement.
2. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 1, wherein, The second authentication request includes a generated session identifier; The process of generating the session identifier includes: Send a registration request to the vehicle cloud, and receive the private key and the unique vehicle identification code feedback by the vehicle cloud; In response to receiving the teaming application broadcast by the captain vehicle, send a unified verification code to the vehicle cloud; Receive the unique team identification code assigned by the vehicle cloud; Generate a session identifier according to the current timestamp, the unique vehicle identification code and the unique team identification code.
3. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 2, wherein The second authentication request includes a generated vehicle authentication information; The process of generating the vehicle authentication information includes: Obtain the vehicle speed, the private key feedback by the vehicle cloud, and the generated session identifier and perform homomorphic encryption; Randomly select two large prime numbers that satisfy the mathematical properties of homomorphic encryption, and multiply them to obtain the homomorphic encryption modulus ; Select a random number from the multiplicative group of the homomorphic encryption modulus as the first random number generated during the homomorphic encryption process , generate the encryption key pair and the second random number generated during the homomorphic encryption process ; According to the prime order of the vehicle networking cyclic group generator and the second random number generated during the homomorphic encryption process , according to the formula generate the third random number generated during the homomorphic encryption process ; Use a hash function to combine the encryption key pair and the third random number generated during the homomorphic encryption process with the vehicle speed, the private key feedback by the vehicle cloud, and the generated session identifier to generate combined information; Use the homomorphic encryption operation to encrypt the combined information with the encryption key pair and the second random number generated during the homomorphic encryption process to generate the vehicle authentication information.
4. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 3, characterized in that, The above-mentioned combined information is expressed as: ; In the formula, represents the combined information of the th vehicle to be authenticated, represents a hash function, represents the unique team identification code of the th fleet, represents the current timestamp of the th vehicle to be authenticated in the th fleet, represents the homomorphic encryption modulus of the th vehicle to be authenticated, represents the first random number generated during the homomorphic encryption process of the th vehicle to be authenticated, represents the vehicle speed of the th vehicle to be authenticated, represents the private key received by the th vehicle to be authenticated from the vehicle cloud feedback, represents the third random number generated during the homomorphic encryption process of the th vehicle to be authenticated, represents the unique vehicle identification code of the th vehicle to be authenticated in the th fleet.
5. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 4, wherein, The above-mentioned vehicle authentication information is expressed as: ; In the formula, represents the vehicle authentication information of the th vehicle to be authenticated, represents the th vehicle to be authenticated using the encryption key pair < N i ,B i > and the second random number generated during the homomorphic encryption process to encrypt the combined information .
6. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 5, characterized in that The second authentication request includes a generated vehicle signature. The process of generating the vehicle signature includes: Obtain the vehicle speed, the private key feedback by the vehicle cloud, the encryption key pair, the generated session identifier, the generated vehicle authentication information, and the third random number generated during the homomorphic encryption process, and use a hash function to combine them to generate the vehicle signature; Wherein, the above-mentioned vehicle signature is expressed as: ; In the formula, represents the vehicle signature of the th vehicle to be authenticated.
7. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 6, characterized in that The second authentication request further includes the vehicle speed, the encryption key pair, and the third random number generated during the homomorphic encryption process. The second authentication request is expressed as: ; In the formula, represents the second authentication request of the 8. The blockchain-enhanced in-vehicle network internal closed-loop authentication method according to claim 1, characterized in that, Using the PBFT consensus algorithm to submit the verified second authentication request to the blockchain network includes: Set the captain vehicle as the main node and the remaining vehicles as participating nodes; Use the client to initiate an authentication request to the main node. The main node receives the authentication request and generates a pre-prepared message containing the authentication request, which is broadcast to all participating nodes; The participating nodes receive and verify the pre-prepared message: If the verification passes, the participating nodes store the pre-prepared message and broadcast a prepared message to indicate that they are ready to verify the pre-prepared message; The main node and the participating nodes listen for the prepared messages from other nodes. If the main node receives the prepared messages from more than a preset threshold number of participating nodes, it generates and submits a commit message to all participating nodes to indicate the verification of the pre-prepared message; The participating nodes receive and verify the commit message: If the verification passes and it is confirmed that the commit messages received from more than a preset threshold number of participating nodes are legal, the request operation is executed; After the request operation is completed, the participating nodes that have executed the request operation generate a response message, which is forwarded to the client through the main node to confirm that the authentication request has been successfully processed.
Citation Information
Patent Citations
Vehicle networking method and device based on block chain hybrid consensus mechanism
CN116156509A
Motorcade trust management system and method based on fuzzy logic and deep learning
CN116647840A