Vehicle-mounted ad hoc network security communication system and method based on NTRU lattice cryptosystem

By adopting a secure communication system based on the NTRU cryptographic system in the on-board ad hoc network, the problems of insufficient security of message transmission and low computing efficiency are solved, and efficient and secure message transmission and identity authentication are achieved, which is suitable for on-board environments.

CN120200750AActive Publication Date: 2025-06-24CHANGCHUN UNIV OF TECH

Patent Information

Application Number
CN202510679070.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-24
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

In the existing on-board ad hoc network, message transmission is insufficient, computational efficiency is low, privacy protection is difficult, and it is difficult to meet the requirements of real-time and low computing costs.

Method used

The vehicle-mounted network secure communication system based on the NTRU cryptographic system is adopted to design an efficient message signature and verification solution. Through the key generation module, message signature module, message encryption module, message decryption module, message verification module, identity authentication module, key exchange module and certificate management module, the integrity of the message and the validity of identity authentication are ensured.

Benefits of technology

It improves the security and efficiency of message transmission in the on-board ad hoc network, effectively deals with security threats such as identity forgery, data tampering and replay attacks, reduces the computational complexity of signature generation and verification, and is suitable for on-board equipment with limited resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200750A_ABST
    Figure CN120200750A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of digital information transmission, and relates to a vehicle-mounted ad hoc network security communication system and method based on an NTRU lattice cryptosystem, and the system comprises a message signature module, a message encryption module, a message decryption module, an identity authentication module, and a key exchange module. The message signature module carries out signature by utilizing a private key and a random polynomial dynamically generated by a pseudo-random number generator based on an NTRU lattice cryptosystem; the message encryption module encrypts a to-be-sent message by randomly selecting a temporary polynomial and combining a public key of a receiver; the message decryption module is used for decrypting the received ciphertext # imgabs1 # by using a private key and an inverse element # imgabs0 # of a module p of the private key; the identity authentication module is used for performing identity authentication; the key exchange module realizes secure key exchange between communication nodes in the vehicle-mounted ad hoc network through an improved Blom key distribution protocol. The system improves the security and communication efficiency of the vehicle-mounted network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of digital information transmission, and relates to a secure communication system and method for vehicular ad hoc networks based on the NTRU lattice cryptosystem. Background Art

[0002] With the development of vehicular ad hoc networks (VANETs), vehicle-to-vehicle communication plays a crucial role in intelligent transportation and autonomous driving. However, VANETs face security threats such as data tampering and identity forgery, which affect system stability and traffic safety. To ensure the authenticity and integrity of communication data, message signature and authentication technologies have become key protection means. Currently, vehicular communication mainly relies on traditional public key infrastructure (PKI) and signature algorithms (such as RSA, DSA), but these algorithms have high computational complexity and slow processing speed, making it difficult to adapt to the vehicular environment.

[0003] Chinese Patent CN 117614624 A discloses "A Secure Trust Method for Identity Authentication Based on Key Agreement in the Internet of Vehicles". This method first generates a pseudo-random number, then generates a signature based on the elliptic curve cryptosystem, generates a session key using the Blom key distribution protocol, and finally authenticates the communication entity through a three-way two-way authentication method. This method has advantages such as short keys and fast calculation speed compared to the commonly used RSA signature algorithm based on the large prime number factorization problem. However, how to further improve the key generation, encryption, and decryption speeds while ensuring the security level has become a difficult problem in the industry.

[0004] In addition, the development of quantum computing poses a risk of cracking traditional encryption algorithms. Therefore, more efficient and quantum-resistant solutions are needed. Lattice cryptography has received extensive attention due to its anti-quantum attack characteristics. In particular, the signature algorithm based on NTRU combines efficiency and security and is suitable for vehicular ad hoc networks. However, existing NTRU-based solutions still have problems with computational efficiency and implementation complexity, making it difficult to meet the requirements of vehicular ad hoc networks for real-time performance and low computational cost. Therefore, there is an urgent need for a signature scheme that combines security and efficiency to improve the communication security and performance of vehicular ad hoc networks. Summary of the Invention

[0005] To solve the problems of insufficient message transmission security, low computational efficiency, and difficult privacy protection in existing vehicular ad hoc networks, the present invention provides a secure communication system for vehicular ad hoc networks based on the NTRU lattice cryptosystem, aiming to improve the security and efficiency of message transmission in vehicular ad hoc networks. By introducing the NTRU lattice cryptosystem, an efficient message signature and verification scheme is designed to ensure the integrity of messages and the effectiveness of identity authentication, effectively coping with security threats such as identity forgery, data tampering, and replay attacks in vehicular ad hoc networks, and improving the security and communication efficiency of vehicular networks.

[0006] To achieve the above object, the present invention adopts the following technical solutions: A vehicular ad hoc network secure communication system based on the NTRU lattice cryptosystem, including a key generation module, a message signature module, a message encryption module, a message decryption module, a message verification module, an identity authentication module, a key exchange module, and a certificate management module; the improvement is that it further includes a pseudorandom number generator; Among them, the key generation module uses the NTRU lattice cryptosystem to generate a public key and private key pair for each communication node in the vehicular ad hoc network, and publishes and manages the public key through the certificate management module; The message signature module generates a signature based on the NTRU lattice cryptosystem using the private key and a random polynomial dynamically generated by the pseudorandom number generator, generating a signature polynomial , ; where is the private key polynomial of the sender, is the message hash value, is a temporarily generated random polynomial by the sender, is the current timestamp, is the modulus in the NTRU encryption process, is the symbol for polynomial convolution operation, is the symbol for exclusive OR operation, is the symbol for modulo operation; The message encryption module obtains the receiver's public key through the certificate management module, encodes the message to be sent into a message polynomial m with a degree less than and the absolute value of the coefficient at most , encrypts the message to be sent by randomly selecting a temporary polynomial and combining it with the receiver's public key to form the final ciphertext ; ; where is a temporarily generated random polynomial for the randomness of the encryption operation, , are both moduli in the NTRU encryption process, is the current timestamp, used to bind the uniqueness of each encryption to prevent replay attacks, is the receiver's public key polynomial, obtained through the certificate management module, and H represents the hash operation; The message decryption module decrypts the received ciphertext using the private key and its inverse modulo p to restore the plaintext, and the decrypted message polynomial ; where, , , a and b are intermediate calculation values, A temporary random polynomial dynamically generated for the recipient to enhance randomness in the decryption process. Is the current timestamp, combined with the temporary random polynomial To increase the uniqueness of each decryption and prevent replay attacks; For the message verification module, the recipient obtains the public key of the sender through the certificate management module and separates the signature polynomial from the received data ; Use the public key polynomial of the sender to perform polynomial convolution and modular operations on the signature polynomial To recover the hash value and the random polynomial; then perform a hash operation on the decrypted message polynomial And compare it with the recovered hash value; at the same time, verify the validity of the random polynomial; if the hash values are consistent and the random polynomial is valid, it is determined that the message is complete and the source is legal, and enter the subsequent processing flow; For the identity authentication module, the identity authentication of vehicle network nodes is completed through a challenge - response protocol based on NTRU lattice cryptography to ensure the identity legality of both communication parties; For the key exchange module, a secure key exchange between communication nodes in a vehicular ad - hoc network is achieved through an improved Blom key distribution protocol.

[0007] As a preference of the present invention, in the key generation module, the generation process of the public key and the private key is as follows: Select two random Degree polynomials And To generate keys; use the extended Euclidean algorithm to find the inverse of If the inverse of Cannot be found, then re - select the polynomials , And Are respectively Multiplicative inverses modulo And modulo , that is ; Calculate , Is the temporary random polynomial, and the public key is , and the private key is , and the coefficients of the random polynomial of the private key are randomly selected from {-1, 0, 1} by a pseudo - random number generator; Among them, And Are the moduli in the NTRU encryption process, The value of Is from 2 to 5 to ensure the irreversibility of polynomial operations, Represents the public key polynomial, is the symbol of modulo operation; N is the degree of the polynomial, and the value range is 509 ≤ N ≤ 1277.

[0008] As an optimization of the present invention, the steps for the identity authentication module to perform identity authentication are as follows: The verifier generates a random challenge polynomial , the degree of the polynomial is , and the coefficients are randomly selected from the set L of sparse polynomials with degrees less than N and absolute values of coefficients not exceeding a set threshold; at the same time, the current timestamp T is recorded, and challenge data is generated and the timestamp T is transmitted synchronously through the protocol and sent to the prover; The prover verifies the validity of the current timestamp T. If it times out, the challenge is discarded; if it is valid, a random polynomial dynamically generated using the private key f and the pseudorandom number generator is used to sign the challenge polynomial and the signed polynomial is returned to the verifier; The verifier obtains the public key of the prover from the certificate management module, uses the public key to perform an inverse operation on the signed polynomial to recover the hash value and the random polynomial; then performs a hash operation on the random challenge polynomial, compares it with the recovered hash value, and at the same time verifies the timestamp validity of the random polynomial

[0009] As an optimization of the present invention, the key exchange module mainly performs key exchange by exchanging the public column vectors and of both parties; when node needs to communicate with , node calculates the shared key : ; Node calculates the shared key : ; Among them, the private key vector of node , S is a D×D symmetric matrix, the elements of which are randomly selected from the finite field GF(q) and satisfy invertibility, and q is a large prime number; is the D×D public matrix 's th column polynomial vector, and the elements of the public matrix are random polynomials with degrees < N and coefficient ranges [-(p - 1) / 2, (p - 1) / 2]; is for node Private key vector

[0010] As a preference of the present invention, the certificate management module is responsible for the full life cycle management of public key certificates in the vehicular ad hoc network, including certificate generation, distribution, revocation, and update.

[0011] As a preference of the present invention, the pseudo-random number generator is a pseudo-random number generator conforming to the ANSI X9.17 standard, and the pseudo-random number generator uses triple DES encryption to ensure the unpredictability of the random polynomial or random number.

[0012] As a preference of the present invention, the temporary random polynomial the temporary random polynomial dynamically generated by the sender the temporarily generated random polynomial the temporary random polynomial dynamically generated by the receiver all belong to L, where L is the set of all sparse polynomials with degrees less than N and absolute values of coefficients not exceeding a set threshold, that is, the set of random polynomials; the coefficients of the random polynomial are selected from {-1, 0, 1}.

[0013] The present invention also provides a vehicular ad hoc network secure communication method based on the NTRU lattice cryptosystem. The method includes the following steps: Step 1. Use the NTRU lattice cryptosystem to generate the public key and private key pairs of each communication node in the vehicular ad hoc network. The communication node publishes its public key to the above-mentioned secure communication system and manages it through the certificate management module. The certificate management module is responsible for the distribution, revocation, and update of the public key certificate to ensure the validity of the public key; Step 2. When the sender needs to send a message, use the private key to sign the message to be sent. During the signature process, add the random polynomial dynamically generated by the pseudo-random number generator. Use the NTRU signature algorithm to complete, making each signature unique. The generated signature data and the original message are sent to the message encryption module together. The message encryption module requests the public key certificate of the receiver from the certificate management module, encodes the message to be sent into a message polynomial conforming to the NTRU lattice cryptosystem, randomly selects a temporary polynomial and encrypts the message to be sent using the public key of the receiver. After that, the signed and encrypted message is transmitted to the receiver through the vehicular ad hoc network; Step 3. After receiving the message, the receiver first uses the private key and its inverse modulo p to decrypt the received ciphertext to recover the plaintext; then requests the public key certificate of the sender from the certificate management module. First, restore the hash value and the random polynomial through the signature verification operation, and then for the decrypted message polynomial Perform hashing and compare it with the hash value obtained from the signature verification operation; at the same time, verify the validity of the random polynomial; if the hash values are consistent and the random polynomial is valid, it proves that the message has not been tampered with during transmission and is indeed sent by a legitimate sender, then execute step 4 to continue processing the message; if the verification fails, reject the message; Step 4. Identity authentication; The receiver and the sender complete the identity authentication through the challenge-response method based on the NTRU lattice cryptography to verify the legitimacy of each other's identities; the verifier will generate a random challenge polynomial, and the prover signs the random challenge polynomial with the private key and returns it. The generated signature is verified by the verifier using the public key of the prover to prevent replay attacks; if the identity authentication passes, then execute step 5; if the identity authentication fails, reject the communication; Step 5. Perform key negotiation through an improved Blom key distribution protocol to determine the session key; Step 6. Communication; The receiver uses the private key to perform NTRU signature on the response message and encrypts it with the negotiated session key, and then returns the data to the sender; after receiving it, the sender first decrypts it with the session key and then verifies the signature with the public key of the receiver; after confirming that the data is valid, parse the data; If the communication between the sender and the receiver is stable, subsequent data exchanges are directly encrypted using the session key; If the sender leaves the coverage range of the receiver, it is necessary to re-perform identity authentication and key negotiation with a new receiver.

[0014] As a preference of the present invention, during the communication process, the abnormal behavior management module monitors abnormal behaviors and executes certificate revocation or security response measures when an abnormality is detected. By revoking the certificate, it prevents the device from continuing to conduct insecure communication, and at the same time dynamically updates the certificate revocation list.

[0015] As a preference of the present invention, during identity authentication, three-party identity authentication is used to prevent man-in-the-middle attacks. During the three-party authentication process, the on-vehicle unit, the roadside unit, and the service provider respectively need to verify each other's certificates and confirm their identities.

[0016] As a preference of the present invention, during identity authentication, a pseudonym certificate issued by a pseudonym certificate authority is attached. After receiving the identity authentication request, the prover first checks whether the pseudonym certificate is issued by a trusted pseudonym certificate authority and verifies whether the signature of the pseudonym certificate is correct to ensure its integrity; subsequently, check the validity period of the pseudonym certificate to ensure that it has not expired, and at the same time query the certificate revocation list or use the Online Certificate Status Protocol to verify whether the pseudonym certificate has been revoked; if the signature of the pseudonym certificate is correct, not expired, and not revoked, the prover considers the pseudonym certificate valid and continues with the next step of the identity authentication process; otherwise, the identity authentication fails.

[0017] Advantages and beneficial effects of the present invention: (1) Currently, most VANET (Vehicular Ad Hoc Network) systems adopt signature and encryption schemes based on elliptic curves (ECDSA) or RSA. The present invention uses NTRU format for signature and encryption. This lattice-based cryptography scheme has more advantages in resisting quantum attacks compared to traditional public key systems, can effectively resist the threat of quantum computing to existing encryption technologies, and thus ensure data security. At the same time, based on the optimization of the traditional NTRU algorithm, the present invention improves the algorithm structure and calculation efficiency (optimize the convolution operation, reduce the number of operations, and improve the efficiency of signature generation and verification; optimize the modular operation process, reduce the computational complexity, improve the computational accuracy, and ensure the signature process is fast and accurate), reduces the computational complexity of signature generation and verification, improves the overall computational efficiency, meets the requirements of vehicular ad hoc networks for real-time and high efficiency, and is applicable to resource-constrained on-board units (OBUs). In addition, traditional VANET mainly adopts two-way authentication (OBU and RSU) or centralized CA authentication. The present invention introduces VSP (Service Provider) as a third party to form a three-party mutual authentication mechanism of OBU - RSU - VSP, making the RSU not only a relay node but also able to participate in identity authentication and key negotiation with the VSP; this method improves the reliability of authentication and also makes the communication between vehicles more secure.

[0018] (2) The present invention uses the Blom key distribution protocol for key negotiation. Different from the common Diffie-Hellman (DH) key exchange, the Blom protocol allows any two legitimate nodes to directly calculate the session key without additional key exchange, which is very beneficial for the highly dynamic environment of VANET; the Blom + NTRU combination makes key negotiation more efficient and has the ability to resist quantum.

[0019] (3) The present invention combines NTRU signature and pseudonym certificate mechanism at the same time, not only supports identity authentication, but also optimizes privacy protection by regularly replacing pseudonym certificates, so that the OBU will not be maliciously tracked during long-term communication, while most existing VANET solutions still mainly rely on traditional pseudo-identity switching strategies in terms of privacy protection.

[0020] (4) In the present invention, the pseudonym certificate is mainly used to enhance privacy protection and prevent external attackers from inferring the driving trajectory or identity information of a vehicle by long-term tracking of the vehicle's communication records. The pseudonym certificate is still issued by a certificate authority (such as PCA), but it does not bind to the real identity of the vehicle. Instead, it uses a periodically changing pseudonym; the pseudonym certificate is replaced every once in a while (such as every few minutes or hours), so that the communication records of the same vehicle cannot be associated for a long time. Even if an attacker intercepts the message sent by the OBU, due to the regular update of the pseudonym certificate, it is difficult for the attacker to track the OBU through the public key for a long time.

[0021] (5) In the present invention, the Blom key distribution protocol is adopted during key negotiation. The Blom key distribution protocol plays a role in secure key negotiation throughout the process, enabling the OBU, RSU, and VSP to dynamically calculate the shared key (session key) without leaking the key, thereby enhancing the confidentiality and anti-attack ability of vehicle-to-everything (V2X) communication.

[0022] (6) In the present invention, the entire V2X system performs strict identity authentication, signature encryption, certificate revocation, etc. through multiple certificate authorities, ensuring the communication security between vehicles, roadside units, and service providers; all messages are signed and encrypted to ensure the integrity and confidentiality of information under malicious attacks; in addition, the certificate management and abnormal behavior management mechanisms further enhance the anti-attack ability of the system, ensuring that all devices in the system communicate under trusted conditions.

[0023] (7) The present invention adopts a challenge-response mechanism and a three-way authentication method, enhancing the ability to prevent replay attacks and supporting an efficient identity authentication and key exchange process. Compared with traditional elliptic curve cryptosystems and RSA algorithms, the present invention significantly improves the computing efficiency, reduces the bandwidth and storage requirements while ensuring the same security level, and is suitable for wide application in vehicular ad hoc networks.

[0024] (8) The present invention uses the NTRU lattice cryptosystem to generate public and private key pairs, significantly reducing the key length and computational complexity while ensuring security. Moreover, by using the NTRU-based signature algorithm, the messages in vehicle communication can be signed and encrypted to ensure the integrity and confidentiality of the messages during transmission. In addition, the present invention adopts a pseudonym certificate mechanism. By randomly switching the pseudonym certificate and serial number, the leakage of vehicle identity is prevented, further enhancing user privacy protection and avoiding the leakage of the vehicle's real identity. The combination of the pseudonym certificate mechanism and the NTRU signature mechanism further enhances privacy protection through dynamic certificate rotation.

[0025] (9) The method provided by the present invention can operate stably in a changing communication environment, effectively ensure the security of vehicle-mounted communication, and ensure the authenticity and non-tamperability (integrity) of information. At the same time, the optimized algorithm reduces the computing resources required for signature and verification while maintaining high security, reduces the hardware burden on vehicle-mounted terminals, and improves the scalability of the system and the stability of long-term operation. This solution is compatible with existing vehicle-to-vehicle ad-hoc network architectures, is easy to deploy and integrate, does not require major modifications to the system architecture, and can quickly adapt to actual application requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] By referring to the following description in conjunction with the drawings, and with a more comprehensive understanding of the present invention, other objects and results of the present invention will become clearer and easier to understand. In the drawings: Figure 1 is a structural block diagram of the vehicle-to-vehicle ad-hoc network secure communication system of the present invention; Figure 2 is a flowchart of the vehicle-to-vehicle ad-hoc network secure communication method of the present invention; Figure 3 is a comparison chart of the key lengths of three signature schemes provided by the present invention; Figure 4 is a comparison chart of the operation efficiency of three signature schemes provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] To enable those skilled in the art to better understand the technical solutions and advantages of the present invention, the present application will be described in detail below with reference to the drawings, but is not used to limit the protection scope of the present invention.

[0028] Embodiment 1:

[0029] As Figure 1 shown, this embodiment provides a vehicle-to-vehicle ad-hoc network secure communication system based on the NTRU lattice cryptosystem, including a key generation module, a message signature module, a message encryption module, a message decryption module, a message verification module, an identity authentication module, a key exchange module, a pseudo-random number generator, and a certificate management module CA; Among them, the key generation module is used to generate a public key and private key pair for communication nodes in the vehicle-to-vehicle ad-hoc network. The key generation module uses the NTRU lattice cryptosystem to generate a public key and private key pair for each communication node (i.e., vehicle), and publishes and manages the public key through the certificate management module CA; In the present invention, during the key generation process of the NTRU lattice cryptosystem, appropriate NTRU lattice parameters (such as the degree of the polynomial, the modulus, etc.) are first selected according to the requirements of the vehicle-to-vehicle ad-hoc network, and a public key and private key pair are generated based on these parameters.

[0030] To ensure the efficiency and security of vehicular ad hoc networks, reduce the computational overhead, and improve the efficiency, this embodiment adopts an optimized NTRU key generation algorithm, which is as follows: Select appropriate parameters: According to the security requirements of the vehicular communication system, select the parameters of the NTRU algorithm, such as the polynomial degree and the modulus. These parameters should ensure the security of key generation while making the calculation process meet the requirements of low computational resources of vehicular network nodes.

[0031] In this embodiment, the generation process of the public key and the private key is as follows: Select two random -degree polynomials and to generate keys. Use the extended Euclidean algorithm to find the inverse of . If the inverse of cannot be found, reselect the polynomial ; and are the multiplicative inverses of modulo and modulo respectively, that is, ; Calculate , is a temporary random polynomial generated by a pseudorandom number generator, ∈L (L is the set of all sparse polynomials with degrees less than N and absolute values of coefficients not exceeding a set threshold, that is, the set of random polynomials), which is used in the public key generation process. After combining with the current timestamp T, a value for calculating the public key is generated; the public key is , and the private key is ; Among them, and are the moduli in the NTRU encryption process. The value of is from 2 to 5 to ensure the irreversibility of polynomial operations. The value of is 2048 ≤ q ≤ 4096, and at the same time, q > 6p needs to be satisfied to prevent decryption errors. represents the public key polynomial, is the symbol of the modulo operation; is the symbol of polynomial convolution operation, is the symbol of exclusive OR operation. N is the polynomial degree (security parameter), and its value range is 509 ≤ N ≤ 1277. Preferably, N = 677, which meets the NIST post-quantum security Level 3 standard.

[0032] In this embodiment, the private key is a random polynomial generated based on the NTRU lattice cryptosystem. Its coefficients are randomly selected from {-1, 0, 1} by a pseudo-random number generator compliant with the ANSI X9.17 standard, and its invertibility modulo p and modulo q is verified by the extended Euclidean algorithm to ensure quantum-resistant security. When communicating with other nodes, the generated private key is used to sign messages, while the public key is used to verify signatures. In this way, nodes can authenticate each other, ensure the legitimacy of the other party's identity, and prevent identity forgery.

[0033] The message signature module is used to ensure the integrity and immutability of messages during transmission. The sender dynamically generates a random polynomial for signature based on the NTRU lattice cryptosystem using its own private key and a pseudo-random number generator, generating a signature polynomial. Specifically, first, initialize the NTRU parameters: select the polynomial degree N - 1 (the value range is a prime number that meets the post-quantum security standard, recommended to be 509 to 1277), the modulus p (take a small prime number, range 2 to 5), and q (take a large prime number, satisfying q > 6p, range 2048 to 4096); the private key is a randomly generated polynomial, and its coefficients are selected from {-1, 0, 1} and verified for invertibility modulo p and q.

[0034] Signature generation stage: Perform a hash operation on the message to be signed to generate a message digest After that, combine the temporary random polynomial dynamically generated by a pseudo-random number generator compliant with the ANSI X9.17 standard (using triple DES encryption to protect the seed), and generate a unique signature polynomial through NTRU polynomial convolution operation and modular operation , , where is the sender's private key polynomial, is the message hash value, is the temporary random polynomial dynamically generated by the sender, ∈L, is the current timestamp, is the modulus in the NTRU encryption process; check whether the coefficient range of is within

[0035] This embodiment can ensure that each signature is unpredictable due to the dynamic change of the random polynomial. After the signature data is bound to the original message, it is transmitted to the message encryption module.

[0036] The message encryption module obtains the public key of the recipient through the certificate management module CA, encodes the message to be sent into a message polynomial compliant with the NTRU lattice cryptosystem, and randomly selects a temporarily generated random polynomial Encrypt the message to be sent with the signature data using the public key of the recipient to form the final ciphertext; Specifically, convert the original message into a polynomial m of degree less than (the value range is a prime number that meets the post-quantum security standard, usually 509 to 1277), and the coefficient range is in [-(p - 1) / 2, (p - 1) / 2], that is, the absolute value of the coefficient does not exceed (p - 1) / 2, where p is a small modulus with a value range of 2 to 5; during encryption, select a random polynomial (the coefficients are selected from {-1, 0, 1}) from the set L of random polynomials, and L is the set of all sparse polynomials of degree less than N with the absolute value of the coefficients not exceeding a set threshold (usually k sparse is 1 or 2); then, combine with the recipient's public key polynomial h (a polynomial of degree N - 1), and generate the ciphertext through polynomial convolution operation (symbol ) and modular operation ; where q is a large modulus (the value range is 2048 to 4096), q > 6p, represents the hash operation, is the current timestamp, ∈L, represents the encoded message polynomial, and the coefficients of the ciphertext are adjusted to the range [-q / 2, q / 2).

[0037] In this embodiment, the generated ciphertext is transmitted through the vehicle network, and the recipient can decrypt and verify based on his own private key. The whole process relies on lightweight polynomial operations. Compared with the traditional scheme that relies on elliptic curve scalar multiplication, the computational overhead is significantly reduced, and at the same time, through dynamic parameter selection and anti-quantum design, the balance between security and efficiency is ensured.

[0038] For the message decryption module, the recipient uses his own private key and its inverse modulo p to decrypt the received ciphertext and recover the plaintext; Specifically, after the recipient receives the ciphertext , use the private key f (the coefficients are randomly generated from {-1, 0, 1} and verified for invertibility modulo p and q) and its inverse modulo p to decrypt, calculate the intermediate result , and adjust the coefficients to the range (-q / 2, q / 2); perform modulo p operation on a to obtain ; recover the plaintext through the inverse element , and the decrypted message polynomial ; where M is the decrypted message polynomial, a and b are intermediate calculation values, is a temporarily randomly generated polynomial by the recipient, ∈L to enhance randomness during the decryption process, is the current timestamp, combined with a random polynomial to increase the uniqueness of each decryption and prevent replay attacks; For the message verification module, the receiver obtains the sender's public key through the certificate management module CA and uses the sender's public key to perform integrity verification on the decrypted data; first, the hash value and the random polynomial are restored through signature verification operation, and then the decrypted message polynomial is hashed and compared with the hash value obtained from the signature verification operation; at the same time, the validity of the random polynomial is verified; if the hash values are consistent and the random polynomial is valid, it proves that the message has not been tampered with during transmission and is indeed sent by a legitimate sender, confirming the integrity of the message; Specifically, the receiver obtains the sender's public key through the certificate management module and performs integrity verification on the decrypted message polynomial to verify the validity of the signature data and ensure that the message has not been tampered with and the source is legal. The implementation steps are as follows: Public key acquisition and parameter initialization: Obtain the sender's public key polynomial from the certificate management module (the degree of the polynomial is ; where is a prime number that meets the post-quantum security standard, and the value range is ), confirm the NTRU parameter range, and the small modulus value range: ); the large modulus value range: , and satisfies .

[0039] Signature data extraction and preprocessing: Separate the signature polynomial from the received data ; Signature verification operation: Use the sender's public key polynomial to perform polynomial convolution and modular operation on the signature polynomial to restore the hash value and the random polynomial: , represents polynomial convolution operation (coefficient modular multiplication and accumulation), that is, the result is split into the restored hash value and the random polynomial .

[0040] Integrity comparison and random polynomial verification: Hash consistency verification: Hash the decrypted message polynomial (the algorithm is the same as that of the sender, such as SM3 / SHA-256) to generate a local hash value , and compare it with the restored Strict comparison.

[0041] Verification of the validity of random polynomials: Check the random polynomial to see if its generation complies with the ANSI X9.17 standard (based on the current timestamp and seed update mechanism); Verify if the current timestamp is within the valid window (e.g., ±1 second) to prevent replay attacks.

[0042] Processing of verification results: If and it is valid, determine that the message is complete and the source is legal, and enter the subsequent processing flow; if the hash value does not match or the random polynomial times out, determine that the message has been tampered with or illegally sent, and trigger the exception management module (e.g., record logs, notify the Certificate Revocation Authority PCA).

[0043] The identity authentication module completes the identity authentication of in-vehicle network nodes through the Challenge-Response Protocol based on NTRU lattice cryptography, ensuring the identity legality of both communication parties, that is, both communication parties are authorized devices, and preventing attacks with forged identities; Specifically, the identity authentication module verifies the identity legality of in-vehicle network nodes (such as on-vehicle OBU and roadside unit RSU) through the Challenge-Response Protocol based on NTRU lattice cryptography, ensuring that both communication parties are authorized devices and resisting spoofing attacks. The implementation steps are as follows: Challenge generation (Verifier → Prover): Verifier (the verifying party, such as RSU): Generate a random challenge polynomial ; The degree of the polynomial is (N is a security parameter, and the value range is ); The coefficients are randomly selected from the set L (sparse polynomial, the absolute value of the coefficient ≤ k, usually k sparse = 1 or 2); Add the current timestamp T (accurate to milliseconds), generate the challenge data , and synchronously transmit the timestamp T through the protocol and send it to the Prover.

[0044] Response generation (Prover → Verifier): Prover (the proving party, such as OBU), verify the validity of the current timestamp T (such as the time window ±1 second), and discard the challenge if it times out; if it is valid, use the private key f (the coefficients are selected from {-1, 0, 1}, satisfying the modulo and reversibility) to sign the challenge polynomial to generate the signature polynomial ; Among them, To perform a hash operation on the challenge polynomial ; is a dynamic random polynomial generated by a pseudo-random number generator conforming to the ANSI X9.17 PRNG standard, ∈L; Combine the signature with the current timestamp to form the response data and return it to the Verifier.

[0045] Response Verification (Verifier): Obtain the Prover public key polynomial from the certificate management module and use the public key polynomial h to perform an inverse operation on the signature polynomial to recover the hash value and the random polynomial: ; Calculate the local hash and strictly compare it with the recovered ; Verify the timestamp validity of the random polynomial (the process is the same as that in the challenge ). If the hashes are consistent and the timestamp is valid, the authentication passes; otherwise, it is determined as an illegal node, triggering an alarm and terminating the session.

[0046] In this embodiment, the identity authentication module can prevent man-in-the-middle attacks and protect the security of the system through multi-party identity authentication (such as OBU, RSU, VSP); The key exchange module implements secure key exchange between communication nodes in the vehicular ad-hoc network based on the Blom protocol, ensuring the security and confidentiality of the keys during the communication process. During the key exchange process, both parties exchange keys to ensure that the subsequent encryption process of the communication is protected. The design of the key exchange protocol improves efficiency and security, ensuring the security of information transmission in any network environment.

[0047] Specifically, the key exchange module (based on the Blom protocol) realizes secure key exchange between communication nodes (such as OBU and RSU) in the vehicular ad-hoc network (VANET) through an improved Blom key distribution protocol, ensuring that the generation and distribution of dynamic session keys between nodes meet the requirements of quantum-resistant attacks and lightweight calculations. The implementation steps are as follows: 1. System initialization: Parameter definition: Security threshold k security (the maximum number of anti-captured nodes, with the value range 50 ≤ k security ≤ 200); Finite field GF(q), where q is a large prime number (consistent with the NTRU parameters, 2048 ≤ q ≤ 4096); The public matrix dimension D (takes values of k security +1, i.e., D = k security +1).

[0048] Matrix generation: Generate a D×D symmetric matrix S, whose elements are randomly selected from GF(q) and satisfy invertibility; Generate a D×D public matrix G, whose elements are random polynomials (degree < N, coefficient range [-(p - 1) / 2, (p - 1) / 2], compatible with NTRU parameters).

[0049] 2. Private key vector distribution Node registration: Each node (such as OBU) is assigned a unique identity identifier (such as vehicle-mounted MAC address or digital certificate); For the node Calculate the private key vector : ; where is the th column polynomial vector of the matrix

[0050] Private key vector storage: The node Securely stores (the polynomial vector of length D), and destroys the matrix S to prevent leakage.

[0051] 3. Dynamic key negotiation Session key generation: When the node communicates with the two parties exchange the public column vectors and ; The node calculates the shared key :

[0052] The node calculates the shared key :

[0053] Guaranteed by matrix symmetry = , as the session key.

[0054] In this embodiment, the matrix operation of the Blom protocol is combined with the NTRU polynomial convolution. The elements of the public matrix G are NTRU-compatible polynomials (with coefficient range [-(p - 1) / 2, (p - 1) / 2]), and the lattice cryptography characteristics of NTRU are used to resist quantum computing attacks. In addition, this module can be designed with a dynamic update mechanism, that is, the public matrix G can be updated periodically (such as every 24 hours) to prevent the risk of long-term key exposure.

[0055] The certificate management module (CA) is responsible for the full life cycle management of public key certificates in Vehicular Ad Hoc Networks (VANETs), including certificate generation, distribution, revocation, and update. It combines the NTRU lattice cryptosystem to resist quantum computing attacks and ensures the legitimacy of node identities and the security of communication links. The implementation steps are as follows: 1. System initialization and parameter configuration Definition of NTRU parameters: Degree of polynomial N (a prime number meeting the post-quantum security standard, with the value range ); Small modulus and large modulus .

[0056] Certificate template: Adopt the lightweight X.509 certificate format extension and embed the NTRU public key polynomial h (in the format of a coefficient list, with the range ); The certificate fields include: Node identifier such as the on-vehicle MAC address or VIN code; Public key polynomial ; Validity period (dynamically adjusted, default 24 hours); Signature of the issuing authority (generated based on the private key of the NTRU-based certificate issuing authority ).

[0057] 2. Certificate generation and distribution Node registration: New node i such as OBU / RSU generates an NTRU key pair ; Submits a registration request to the certificate issuing authority (CA), including and .

[0058] Certificate signing: After the CA verifies the legitimacy of the node identity, it uses the private key to sign the certificate content and generate a certificate file : signature polynomial ; where is a hashing operation (hashing function), is an anti-replay random polynomial generated by a pseudo-random number generator that complies with the ANSI X9.17 standard, ∈L.

[0059] Send to the nodes and the radio network units (RSUs) of the entire network.

[0060] 3. Certificate Revocation List (CRL) Management Revocation Trigger Conditions: The private key of the node is leaked, the identity is abnormal, or the session key negotiation fails more than the threshold number of times.

[0061] CRL Generation and Broadcasting: The CA periodically generates a revocation list CRL, which contains the IDs of the revoked certificates and the revocation current timestamp; the CRL format is polynomial encoding (coefficient range ), and is broadcast to the entire network through the RSU, and the update period ≤ 5 minutes; the NTRU signature of the CA is attached during broadcasting to ensure the integrity of the list.

[0062] 4. Certificate Update and Cooperative Authentication Periodic Update: Before the expiration of the certificate validity period, the CA automatically generates a new certificate , and pushes it to the nodes through the RSU; after the nodes verify the CA signature of the new certificate, they replace the old certificate without re-registration.

[0063] In this embodiment, in the challenge-response protocol, the verifier (such as the RSU) obtains the public key polynomial of the other party through the certificate management module , and checks whether it is in the latest CRL; if the certificate is valid and the signature verification passes, the identity is determined to be legal.

[0064] Furthermore, in this embodiment, the pseudo-random number generator is a pseudo-random number generator that complies with the ANSI X9.17 standard. The ANSI X9.17 pseudo-random number generator uses triple DES encryption to ensure the unpredictability of the random polynomial or random number, so as to improve the security of the random polynomial or random number.

[0065] Embodiment 2: As Figure 2 shown, this embodiment provides a vehicle ad-hoc network secure communication method based on the NTRU lattice cryptosystem. The method includes the following steps: Step 1. Use the NTRU lattice cryptosystem to generate the public and private key pairs for each communication node in the vehicular ad hoc network. The communication node publishes its public key to the secure communication system of Embodiment 1 and manages it through the certificate management module CA. The certificate management module CA is responsible for the distribution, revocation, and update of the public key certificate to ensure the validity of the public key. In this embodiment, the public key certificate is mainly used for identity authentication to ensure the true identity of the communication entity. It is issued by the certificate management module CA, binding the true identity of the communication entity (such as the VIN code, i.e., the unique identification information of the vehicle) with the public key to ensure the credibility of the public key. The communication entities include on-board units (OBUs), roadside units (RSUs), and service providers (VSPs). Step 2. When the sender needs to send a message, use its own private key to sign the message to be sent. During the signing process, add a random polynomial generated by a pseudo-random number generator (ANSI X9.17 PRNG). The signing is completed using the NTRU signature algorithm to make each signature unique (even for the same message, due to the addition of some random factors during the signing process, the signature values generated each time will be different). The generated signature data is sent to the message encryption module together with the original message. The message encryption module requests the public key certificate of the recipient from the CA, encodes the message to be sent into a message polynomial that conforms to the NTRU lattice cryptosystem, and randomly selects a temporary polynomial and encrypts the message to be sent using the public key of the recipient. Then, the signed and encrypted message is transmitted to the recipient through the vehicular ad hoc network.

[0066] For example: When an on-board unit (OBU) enters a certain area, the OBU needs to request the traffic signal status and the road conditions ahead from a nearby roadside unit (RSU). Then the OBU first generates a request message containing information such as location, speed, direction, and current timestamp, and uses the NTRU signature algorithm for integrity protection. At the same time, it encrypts the message with the public key of the RSU to ensure communication security. Subsequently, the OBU sends the encrypted message to the RSU. In this embodiment, the OBU and the RSU obtain each other's public keys by exchanging public key certificates during communication, so as to perform encryption and signature verification.

[0067] Step 3. After receiving the message, the recipient first uses its own private key and the inverse of its modulus p to decrypt the received ciphertext to recover the plaintext. Then it requests the public key certificate of the sender from the CA. First, it recovers the hash value and the random polynomial through the signature verification operation, and then for the decrypted message polynomial Perform hashing and compare it with the hash value obtained from the signature verification operation; at the same time, verify the validity of the random polynomial; if the hash values are consistent and the random polynomial is valid, prove that the message has not been tampered with during transmission and is indeed sent by a legitimate sender, and execute step 4 to continue processing the message; if the verification fails, reject the message; For example: when the RSU receives a message, it first decrypts the message using its own private key, verifies the signature using the OBU's public key, and at the same time checks whether the OBU's public key certificate is valid; if the verification passes, the RSU processes the OBU's request, such as querying the current traffic light status, and encapsulates the result into a response message; Step 4. Identity authentication: The receiver and the sender complete identity authentication through a challenge-response method based on the NTRU lattice cryptography to verify the legitimacy of each other's identities and prevent identity forgery attacks. Among them, the authenticator (such as the RSU) will generate a random challenge polynomial, and the authenticated party (such as the OBU, also known as the prover) needs to sign the random challenge polynomial with its own private key and return it. The generated signature will be verified by the authenticator (also known as the verifier) using the public key of the authenticated party to prevent replay attacks; if the identity authentication passes, execute step 5; if the identity authentication fails, reject the communication; In this embodiment, when the OBU sends an identity authentication request, it will attach a pseudonym certificate issued by a pseudonym certificate authority (PCA, which is used to issue pseudonym certificates for in-vehicle units and roadside units to prevent user privacy leakage). After receiving the identity authentication request, the RSU or VSP first checks whether the pseudonym certificate is issued by a trusted PCA and verifies whether the signature of the pseudonym certificate is correct (using the public key of the PCA in the pseudonym certificate to verify the signature of the pseudonym certificate. If the verification is successful, it means that the pseudonym certificate is issued by a trusted PCA and has not been tampered with) to ensure its integrity; subsequently, check the validity period of the pseudonym certificate to ensure that it has not expired, and at the same time query the certificate revocation list (CRL) or use the Online Certificate Status Protocol (OCSP) to verify whether the pseudonym certificate has been revoked; if the signature of the pseudonym certificate is correct, not expired, and not revoked, the RSU or VSP considers the pseudonym certificate valid and continues the next step of the identity authentication process; for example, verify the signed message sent by the OBU; otherwise, the identity authentication fails, and the RSU or VSP will refuse to communicate further with the OBU and notify the certificate management module CA or the abnormal behavior management module MA for processing; finally, the verification result will be fed back to the OBU; if the identity authentication passes, enter the subsequent key negotiation and secure communication stage, so as to ensure that the communication devices in the vehicle network have legitimate identities and can interact securely.

[0068] It should be noted that identity authentication only occurs during the first communication exchange, and subsequent communication exchanges will no longer require identity verification.

[0069] Step 5. Perform key negotiation through an improved Blom key distribution protocol to determine the session key: Specifically, when node communicates with , the two parties exchange the public column vectors and ; Node calculates the shared key : ; The private key vector of node ; where is the -th column polynomial vector of the D×D public matrix . The elements of the public matrix are random polynomials with degree < N and coefficient range [-(p - 1) / 2, (p - 1) / 2]; S is a D×D symmetric matrix, the elements of which are randomly selected from GF(q) and satisfy invertibility, where q is a large prime number and 2048 ≤ q ≤ 4096; Node calculates the shared key : ; is guaranteed by the matrix symmetry = as the session key; Step 6. Communication: The receiver (e.g., RUS) uses its own private key to perform NTRU signature on the response message and encrypts it with the session key (shared key) negotiated with the OBU before, and then returns the data to the sender (e.g., OBU); after receiving it, the sender (e.g., OBU) first decrypts it with the session key and then verifies the signature with the public key of the receiver (e.g., RSU) to ensure that the data has not been tampered with; after confirming that the data is valid, the OBU parses the traffic signal status and adjusts the driving strategy in combination with its own speed; If the communication between the OBU and the RSU is stable, subsequent data exchanges can directly use the session key for encryption, such as the OBU periodically sending location updates and the RSU feedback on the congestion of the road ahead, etc.; If the OBU leaves the coverage area of the RSU, it needs to re-authenticate its identity and negotiate keys with a new RSU to ensure communication security. During the whole process, the NTRU signature ensures non-repudiation of messages, the certificate management module CA is responsible for identity authentication, and the session key ensures the confidentiality of subsequent communications.

[0070] Furthermore, in this embodiment, during identity authentication, multi-party identity authentication (such as OBU, RSU, VSP) is adopted to prevent man-in-the-middle attacks and protect the security of the system; during this three-party authentication process, the on-vehicle unit (OBU), roadside unit (RSU), and service provider (VSP) need to verify each other's identities respectively. OBU and RSU: The OBU first sends an identity authentication request to the RSU, and the RSU verifies the OBU's certificate and confirms its identity. RSU and VSP: The RSU sends an identity authentication request through the VSP, and the VSP verifies the RSU's certificate and confirms its identity. OBU and VSP: Guided by the RSU, the OBU sends an identity authentication request to the VSP, and the VSP verifies the OBU's certificate again to ensure the validity of the OBU's identity.

[0071] The present invention introduces the VSP (service provider) as a third party to form a three-party mutual authentication mechanism of OBU - RSU - VSP, enabling the RSU to not only be a relay node but also participate in identity authentication and key negotiation with the VSP; this method improves the reliability of authentication and also makes vehicle-to-vehicle communication more secure.

[0072] The present invention uses the NTRU-Blom hybrid architecture, combines lattice cryptography with a lightweight key distribution protocol to solve the quantum resistance defect of the traditional Blom protocol; this method adopts dynamic security design, the generation of random polynomials strictly follows the ANSI X9.17 standard, and binds the current timestamp (±1 second window) to ensure the uniqueness and anti-replay ability of each communication; key management uses dynamic session keys (updated for each communication) and short-term certificates (forced update every 24 hours), greatly reducing the risk of key leakage; the certificate revocation list (CRL) is updated at the 5-minute level through sharded broadcasting, the network-wide synchronization delay is <1 second, and the entire link binds the current timestamp - random polynomial - hash to achieve dynamic association of message signature, identity authentication, and certificate issuance, making it comprehensively superior to the existing technologies in terms of quantum-resistant security, real-time performance, dynamic scalability, and resource efficiency.

[0073] The present invention conducts a comprehensive comparative analysis on the elliptic curve cryptosystem (LD1), the NTRU lattice cryptosystem (LD2), and the commonly used RSA signature algorithm based on the large prime factorization problem (Solution 3), and focuses on the evaluation from three aspects: security, computational overhead, and communication overhead. In terms of security, the key lengths of the three signature schemes in this solution are compared (in bits), and the results are as Figure 3 shown. From Figure 3 the four groups of data, it can be seen that in terms of security strength, the NTRU scheme with a key length of 347 bits has the same security as the LD1 with 224 bits and the RSA scheme with 2048 bits, reflecting the differences in key lengths among different signature algorithms. In terms of computational overhead, the NTRU scheme has the advantages of shorter key and ciphertext lengths and faster computing speed. Compared with the RSA and elliptic curve signature systems, it can complete encryption and decryption operations more efficiently. In addition, due to the lower storage space requirements and smaller transmission bandwidth of the NTRU scheme, the requirements for system hardware resources are reduced, making it more suitable for applications in environments with lower requirements for processor speed and network bandwidth.

[0074] The operation efficiencies of the above three signature schemes are as Figure 4 shown. From Figure 4 the data, it can be seen that there are significant differences in the operation efficiencies of the three signature schemes. In LD1, based on the elliptic curve cryptosystem, when performing encryption and decryption, 160 rational point scalar multiplication operations need to be executed. In contrast, LD2 based on the NTRU algorithm only involves addition, multiplication, and modulo operations of small integers. Therefore, in the encryption and decryption processes, LD2 performs one convolution operation and two convolution operations respectively. As for Solution 3, it relies on the large prime number problem and requires 17 and 1000 modulo multiplication operations respectively when performing encryption and decryption. It can be seen that at the same security level, the computing speed of LD2 is significantly faster than the other two public key systems, and the computational overheads of the three schemes are shown in Table 1.

[0075] Table 1 Computational Overheads of the Three Schemes Solution Key Generation (ms) Encryption (ms) Decryption (ms) Total Time (ms) Solution Three 4.07 248.21 4.012 256.29 LD1 0.27 9.119 10.472 9.389 LD2 0.014 0.829 0.952 1.795 Generally speaking, LD2 is superior to LD1 in terms of key generation, encryption and decryption speeds. Its overall running speed is about 5.23 times faster than LD1, and compared with Solution 3, it is about 142.84 times faster. This shows that LD2 not only meets the same security standards, but also has significant advantages in computational efficiency, especially suitable for scenarios that require efficient processing.

[0076] The present invention effectively reduces the computational overhead and improves the efficiency of signature generation and verification by optimizing the NTRU signature algorithm, meeting the requirements of vehicular ad hoc networks for real-time and efficiency, and it can operate stably in complex network environments.

[0077] The above uses specific examples to illustrate the present invention, which is only used to help understand the present invention and is not intended to limit the present invention. For those skilled in the art to which the present invention pertains, based on the idea of the present invention, several simple deductions, deformations or substitutions can also be made. Therefore, the protection scope of the present invention shall be subject to the protection scope of the said claims.

Claims

1. A vehicular ad hoc network secure communication system based on the NTRU lattice cryptosystem, comprising a key generation module, a message signature module, a message encryption module, a message decryption module, a message verification module, an identity authentication module, a key exchange module, and a certificate management module; characterized in that, It further includes a pseudo-random number generator; Among them, the key generation module uses the NTRU lattice cryptosystem to generate public and private key pairs for each communication node in the vehicular ad-hoc network, and the public keys are published and managed through the certificate management module; The message signature module generates a signature based on a random polynomial dynamically generated by using a private key and a pseudo-random number generator according to the NTRU lattice cryptosystem, and generates a signature polynomial , ; where is the private key polynomial of the sender, is the message hash value, is a temporary random polynomial dynamically generated by the sender, is the current timestamp, is the modulus in the NTRU encryption process, is the symbol for polynomial convolution operation, is the symbol for exclusive-or operation, is the symbol for modulo operation; The message encryption module obtains the recipient's public key through the certificate management module, encodes the message to be sent into a message polynomial m with a degree less than and the absolute value of the coefficient at most , encrypts the message to be sent by randomly selecting a temporary polynomial and combining it with the recipient's public key to form the final ciphertext ; ; where is a randomly generated temporary polynomial for the randomness of the encryption operation, , are both moduli in the NTRU encryption process, is the current timestamp, is the recipient's public key polynomial, and H represents the hash operation; The message decryption module, where the receiver uses the private key and the inverse of its modulus p to decrypt the received ciphertext and recover the plaintext. The decrypted message polynomial ; where , , a and b are intermediate calculation values, is a temporarily generated random polynomial by the receiver; The message verification module. The receiver obtains the public key of the sender through the certificate management module and separates the signature polynomial from the received data ; performs polynomial convolution and modular operations on the signature polynomial using the public key polynomial of the sender to recover the hash value and the random polynomial; then performs a hash operation on the decrypted message polynomial and compares it with the recovered hash value; at the same time, verifies the validity of the random polynomial; if the hash values are consistent and the random polynomial is valid, it is determined that the message is complete and the source is legal, and the subsequent processing flow is entered; The identity authentication module completes the identity authentication of vehicular network nodes through the challenge-response protocol based on NTRU lattice cryptography to ensure the identity legality of both communication parties; The key exchange module realizes secure key exchange between communication nodes in the vehicular ad-hoc network through an improved Blom key distribution protocol.

2. The on-vehicle ad hoc network secure communication system based on the NTRU lattice cryptosystem according to claim 1, characterized in that, In the key generation module, the generation process of the public key and the private key is as follows: Select two random degree polynomials and to generate keys; Use the extended Euclidean algorithm to find the inverse of . If the inverse of cannot be found, then re-select the polynomials , and are the multiplicative inverses of modulo and modulo respectively, that is, ; Calculate , is a temporary random polynomial, and the public key is , and the private key is . The coefficients of the random polynomial of the private key are randomly selected by a pseudo-random number generator from {-1, 0, 1}; Among them, and are the moduli in the NTRU encryption process. takes values from 2 to 5. takes values such that 2048 ≤ q ≤ 4096, and at the same time, q > 6p must be satisfied. N is the polynomial degree and takes values from 509 ≤ N ≤ 1277.

3. A vehicle ad-hoc network secure communication system based on the NTRU lattice cryptosystem according to claim 1, characterized in that, The steps for the identity authentication module to perform identity authentication are as follows: The verifier generates a random challenge polynomial , the degree of the polynomial is , the coefficients are randomly selected from the set L of sparse polynomials with all degrees less than N and the absolute value of the coefficients not exceeding the set threshold; attach the current timestamp T to generate the challenge data , and synchronously transmit the timestamp T through the protocol and send it to the prover; The prover verifies the validity of the current timestamp T. If it times out, the challenge is discarded; if it is valid, a random polynomial dynamically generated using the private key f and a pseudorandom number generator is used for the challenge polynomial to perform a signature, and the signature polynomial is returned to the verifier; The verifier obtains the prover's public key from the certificate management module and uses the public key to perform an inverse operation on the signature polynomial to recover the hash value and the random polynomial; then, perform a hash operation on the random challenge polynomial, compare it with the recovered hash value, and at the same time verify the timestamp validity of the random polynomial ; If the hash is consistent and the timestamp is valid, the authentication passes.

4. A vehicular ad hoc network secure communication system based on the NTRU lattice cryptosystem according to claim 1, characterized in that, The key exchange module performs key exchange mainly by exchanging the public column vectors of both parties and ; When node communicates with , node calculates the shared key : ; Node Calculate the shared key : ; Among them, the node 's private key vector , S is a D×D symmetric matrix, whose elements are randomly selected from the finite field GF(q), satisfying invertibility, and q is a large prime number; is the public matrix of D×D 's th column polynomial vector, and the elements of the public matrix are random polynomials with degree < N and coefficient range [-(p - 1) / 2, (p - 1) / 2]; is the private key vector of the node .

5. The on-vehicle ad hoc network secure communication system based on the NTRU lattice cryptosystem according to claim 1, characterized in that, The certificate management module is responsible for the full life cycle management of public key certificates in the vehicular ad-hoc network, including certificate generation, distribution, revocation, and update; the pseudo-random number generator is a pseudo-random number generator compliant with the ANSI X9.17 standard, and the pseudo-random number generator uses triple DES encryption to ensure the unpredictability of random polynomials or random numbers.

6. The vehicular ad hoc network secure communication system based on the NTRU lattice cryptosystem according to claim 2, characterized in that, Temporary random polynomial and the temporary random polynomial dynamically generated by the sender and the temporarily generated random polynomial and the temporary random polynomial dynamically generated by the receiver all belong to L, where L is the set of all sparse polynomials with degrees less than N and absolute values of coefficients not exceeding a set threshold, that is, the set of random polynomials; the coefficients of the random polynomial are selected from {-1, 0, 1}.

7. A secure communication method for vehicular ad hoc networks based on the NTRU lattice cryptosystem, characterized in that, This method includes the following steps: Step 1. Use the NTRU lattice cryptosystem to generate public and private key pairs for each communication node in the vehicular ad-hoc network. The communication node publishes its public key to the vehicular ad-hoc network security communication system based on the NTRU lattice cryptosystem described in any one of claims 1 to 6 and manages it through the certificate management module. The certificate management module is responsible for the distribution, revocation, and update of public key certificates to ensure the validity of public keys; Step 2. When the sender needs to send a message, use the private key to sign the message to be sent. During the signing process, add a random polynomial dynamically generated by a pseudorandom number generator. The signing is completed using the NTRU signature algorithm to make each signature unique. The generated signature data is sent to the message encryption module together with the original message. The message encryption module requests the public key certificate of the recipient from the certificate management module, encodes the message to be sent into a message polynomial that conforms to the NTRU lattice cryptosystem, and randomly selects a temporary polynomial and uses the public key of the recipient to encrypt the message to be sent. After that, the signed and encrypted message is transmitted to the recipient through the vehicular ad hoc network; Step 3. After receiving the message, the recipient first uses the private key and its inverse modulo p to decrypt the received ciphertext to recover the plaintext; then requests the public key certificate of the sender from the certificate management module, first recovers the hash value and the random polynomial through the signature verification operation, and then performs a hash process on the decrypted message polynomial and compares it with the hash value obtained from the signature verification operation; at the same time, verifies the validity of the random polynomial; if the hash values are consistent and the random polynomial is valid, it proves that the message has not been tampered with during transmission and is indeed sent by a legitimate sender, and executes Step 4 to continue processing the message; if the verification fails, the message is rejected; Step 4. Identity authentication; The receiver and the sender complete identity authentication through the challenge-response method based on NTRU lattice cryptography to verify the identity legality of the other party; the verifier will generate a random challenge polynomial, and the prover signs the random challenge polynomial with the private key and returns it. The generated signature is verified by the verifier using the public key of the prover; if the identity authentication passes, then execute Step 5; if the identity authentication fails, then reject the communication; Step 5. Perform key negotiation through an improved Blom key distribution protocol to determine the session key; Step 6. Communication; The receiver uses the private key to perform NTRU signature on the response message and encrypts it with the negotiated session key, and then returns the data to the sender; after the sender receives it, it first decrypts it with the session key and then verifies the signature with the public key of the receiver; after confirming the data is valid, parse the data; If the communication between the sender and the receiver is stable, subsequent data exchanges are directly encrypted using the session key; If the sender leaves the coverage range of the receiver, it is necessary to re-perform identity authentication and key negotiation with a new receiver.

8. A secure communication method for vehicular ad hoc networks based on the NTRU lattice cryptosystem according to claim 7, characterized in that, During the communication process, the abnormal behavior management module monitors abnormal behaviors and executes certificate revocation or security response measures when abnormalities are found, and dynamically updates the certificate revocation list at the same time.

9. A vehicle ad-hoc network secure communication method based on the NTRU lattice cryptosystem according to claim 8, characterized in that, During identity authentication, three-party identity authentication is used to prevent man-in-the-middle attacks. During the three-party authentication process, the on-vehicle unit, the roadside unit, and the service provider need to verify each other's certificates and confirm their identities respectively.

10. A secure communication method for vehicular ad hoc networks based on the NTRU lattice cryptosystem according to claim 9, characterized in that, During identity authentication, a pseudonym certificate issued by a pseudonym certificate authority is attached. After receiving the identity authentication request, the prover first checks whether the pseudonym certificate is issued by a trusted pseudonym certificate authority and verifies whether the signature of the pseudonym certificate is correct to ensure its integrity; Subsequently, check the validity period of the pseudonym certificate to ensure that it has not expired. At the same time, query the certificate revocation list or use the Online Certificate Status Protocol to verify whether the pseudonym certificate has been revoked; If the signature of the pseudonym certificate is correct, not expired, and not revoked, the prover considers the pseudonym certificate valid and continues with the next step of the identity authentication process; otherwise, the identity authentication fails.

Citation Information

Patent Citations

  • Secure identity authentication trust method based on key negotiation in Internet of Vehicles

    CN117614624A

  • Wireless network security switch method capable of resisting quantum attacks

    CN107733632A

  • Threshold ECDSA signature method and system based on pseudo-random number generator

    CN117857016A

  • Underwater Internet of Things and multi-party key encapsulation method

    CN118646534A

  • Time-limited key and message dependent open group signature method based on lattice password

    CN119324784A

Cited By

  • Lightweight Internet of Vehicles communication method based on dynamic pseudo-random encryption

    CN120416841A

  • Quantum attack resistant ubiquitous network data security gateway

    CN120546884A

  • Cross-domain multi-mode credible authentication method of high-dynamic network

    CN120582799A

  • A cross-domain multi-mode trusted authentication method for highly dynamic networks

    CN120582799B

  • Power system source network interaction data security encryption verification method, system, device and medium

    CN120710805A