Vehicle-mounted network identity authentication method, device, equipment and storage medium
Through decentralized identity authentication management and dynamic pseudonym mechanism, the identification authentication of on-vehicle networks is optimized, and problems such as single point failure and large computing overhead in on-vehicle networks are solved, thereby achieving efficient and secure vehicle identity authentication and malicious vehicle detection.
Patent Information
- Application Number
- CN202510455198.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-11
AI Technical Summary
In the existing on-board network identity authentication, centralized architectures are prone to single point failure, large computing overhead, slow verification speed and insufficient anonymity, and there is a lack of an effective rapid retreat mechanism to deal with malicious vehicles.
The decentralized identity authentication management solution is adopted, and the trusted center and roadside units jointly maintain the blockchain nodes, generate vehicle pseudonyms using dynamic pseudonyms, optimize digital signature algorithms to generate temporary key pairs, eliminate modular inverse operations, and realize fast signature authentication and malicious vehicle detection.
Effectively avoid single point of failure, ensure data immutability and traceability, ensure vehicle privacy and anonymity, reduce calculation overhead, and quickly identify and cancel malicious vehicles.
Smart Images

Figure CN120301601A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle networking security, and in particular, to a vehicle network identity authentication method, device, equipment and storage medium. Background Technique
[0002] Vehicle network identity authentication specifically refers to authenticating vehicle identities through specific technical means in a vehicle ad-hoc network, exploring the authentication mechanism for large-scale vehicle communication, and facing various challenges in terms of security and resource utilization.
[0003] In related technologies, numerous privacy protection authentication mechanisms for vehicle networking have been proposed by researchers. Most traditional certification authorities adopt a centralized architecture, which is prone to single-point failures and poses potential threats to the overall network security. In addition, some security computations based on bilinear pairings incur significant overhead. Thanks to the emergence of blockchain technology, its decentralized, transparent, and immutable nature not only enhances the security and stability of the system but also eliminates the risk of single-point failures, prompting researchers to start studying the application of blockchain technology in vehicle network identity authentication. However, the elliptic curve digital signature algorithm ECDSA used in the application process requires multiple modular inverse operations during batch verification, resulting in increased computational overhead and slower verification speed, unable to meet the high-frequency and low-latency communication requirements of vehicle ad-hoc networks; in addition, in some cases, the anonymity of vehicles may be compromised, and there is a lack of an effective fast retreat mechanism to deal with malicious vehicles.
[0004] Based on the analysis of the development status of this technical field above, the existing technologies lack a technical solution that eliminates the modular inverse operation in the traditional verification process and adopts a dynamic pseudonym mechanism to ensure that vehicles use different identity identifiers for verification at different times and locations. Summary of the Invention
[0005] The purpose of the present invention is to provide a vehicle network identity authentication method, device, equipment and storage medium, aiming to solve the above problems in the existing technologies.
[0006] According to the first aspect of an embodiment of the present invention, a vehicle network identity authentication method is provided. The method is applied to a consortium chain composed of a trusted center, roadside units, and a blockchain network, and includes:
[0007] Initialize the trusted center, register the roadside unit and vehicle information, and store the successfully registered vehicle verification parameters in the blockchain network;
[0008] Generate a vehicle pseudonym when the vehicle enters the range managed by a certain roadside unit, receive the vehicle pseudonym through the roadside unit, and perform a preliminary authentication of the vehicle identity based on the vehicle verification parameters stored in the blockchain network;
[0009] When a vehicle after preliminary authentication needs to transmit a message, it generates a temporary key pair with inverse operation using an optimized digital signature algorithm, generates a vehicle message signature based on the temporary key pair, and sends the vehicle message signature to the corresponding roadside unit;
[0010] The roadside unit continuously receives the vehicle message signature, performs signature authentication on the vehicle message signature using a single or batch processing method, and allows message transmission after successful signature authentication;
[0011] The roadside unit detects malicious vehicles and revokes their registrations.
[0012] According to a second aspect of an embodiment of the present invention, there is provided an in-vehicle network identity authentication device. The device is applied to a consortium chain composed of a trusted center, roadside units, and a blockchain network, and includes:
[0013] An initialization module for initializing the trusted center, registering roadside unit and vehicle information, and storing the successfully registered vehicle verification parameters in the blockchain network;
[0014] A preliminary authentication module for generating a vehicle pseudonym when a vehicle enters the range managed by a certain roadside unit, receiving the vehicle pseudonym through the roadside unit, and performing preliminary authentication on the vehicle identity based on the vehicle verification parameters stored in the blockchain network;
[0015] A message signature module for generating a temporary key pair with inverse operation using an optimized digital signature algorithm when a vehicle after preliminary authentication needs to transmit a message, generating a vehicle message signature based on the temporary key pair, and sending the vehicle message signature to the corresponding roadside unit;
[0016] A signature authentication module for continuously receiving the vehicle message signature through the roadside unit, performing signature authentication on the vehicle message signature using a single or batch processing method, and allowing message transmission after successful signature authentication;
[0017] A vehicle revocation module for detecting malicious vehicles through the roadside unit and revoking their registrations.
[0018] According to a third aspect of an embodiment of the present invention, there is provided an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the in-vehicle network identity authentication method provided in the first aspect of the present disclosure are implemented.
[0019] According to a fourth aspect of an embodiment of the present invention, there is provided a computer-readable storage medium, on which a program for implementing information transmission is stored. When the program is executed by a processor, the steps of the in-vehicle network identity authentication method provided in the first aspect of the present disclosure are implemented.
[0020] The technical solutions provided by the embodiments of the present invention have the following beneficial effects: By adopting a decentralized identity authentication management solution, the blockchain nodes are jointly maintained by a trusted center and roadside units, effectively avoiding single-point failures and ensuring the immutability and traceability of data; By adopting a dynamic pseudonym mechanism, new pseudonym information is generated each time a vehicle enters the range of a roadside unit, ensuring that the vehicle uses different identity identifiers at different times and locations, and protecting privacy and unlinkability; By optimizing the digital signature algorithm to generate a temporary key pair with an inverse operation added, the complex modular inverse operation in signature generation and verification of traditional algorithms is eliminated, significantly reducing the computational overhead.
[0021] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in one or more embodiments of the present specification or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1 It is a flowchart of the vehicle network identity authentication method according to an embodiment of the present invention;
[0024] Figure 2 It is a schematic diagram of the overall authentication architecture according to an embodiment of the present invention;
[0025] Figure 3 It is a schematic diagram of the symbolic description according to an embodiment of the present invention;
[0026] Figure 4 It is a schematic diagram of the roadside unit registration according to an embodiment of the present invention;
[0027] Figure 5 It is a schematic diagram of the vehicle information registration according to an embodiment of the present invention;
[0028] Figure 6 It is a schematic diagram of the pseudo-identity generation and preliminary authentication according to an embodiment of the present invention;
[0029] Figure 7 It is a schematic diagram of the vehicle network identity authentication device according to an embodiment of the present invention;
[0030] Figure 8 It is a schematic diagram of the electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the following will clearly and completely describe the technical solutions in one or more embodiments of this specification in conjunction with the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this document.
[0032] Method Embodiment
[0033] According to an embodiment of the present invention, a vehicle network identity authentication method is provided. The method is applied to a consortium blockchain composed of a trusted center, roadside units, and a blockchain network. Figure 1 It is a flowchart of the vehicle network identity authentication method according to an embodiment of the present invention, as Figure 1 shown. The vehicle network identity authentication method according to an embodiment of the present invention specifically includes:
[0034] In step S110, initialize the trusted center, register the roadside unit and vehicle information, and store the successfully registered vehicle verification parameters in the blockchain network, specifically including:
[0035] The overall solution adopts decentralized identity management. The trusted center and roadside units in the consortium blockchain architecture jointly maintain the blockchain nodes. The trusted center TA is responsible for system parameters and public-private key pairs, and the roadside unit RSU is responsible for verifying vehicle identities and maintaining the blockchain ledger. Vehicle-related information is maintained in the blockchain network to assist the roadside unit in verification;
[0036] The object to be authenticated is a vehicle. Each vehicle is equipped with an on-board unit OBU, which uses DSRC technology to communicate with the outside world. The OBU has limited computing power and is equipped with a trusted platform database TPD for storing and generating signature keys for encrypted messages. The vehicle must first register with the trusted center and pass the identity verification of the RSU in its area before it can communicate with the outside world normally. Figure 2 It is a schematic diagram of the overall authentication architecture according to an embodiment of the present invention, as Figure 2 shown, which shows a consortium blockchain system architecture including a trusted center authorization agency TA, roadside units, and a blockchain network for vehicle identity authentication in a vehicle network.
[0037] Figure 3 It is a schematic diagram of the symbolic description according to an embodiment of the present invention, as Figure 3 shown, which shows important symbols and their related descriptions.
[0038] In the embodiment of the present invention, the PBFT consensus mechanism is adopted to ensure the consistency of node vehicle identity information, avoid single-point failures, and ensure the immutability and traceability of data;
[0039] The initialization of the trusted center specifically includes:
[0040] Randomly generate two prime numbers p and q by the trusted center, and define the elliptic curve Ε: y 2 =x 3 +ax + b (mod p) in the finite field Fp, where a and b are parameter terms in the elliptic curve, and (x, y) represents the elliptic node coordinates. Generate a cyclic additive group G of order prime number q based on the prime number p, and obtain the generator P of the cyclic additive group G. Among them, the condition in the cyclic additive group G is 4a 3 +27b 2 (mod p) ≠ 0;
[0041] Generate a random number by the trusted center as the institutional private key, where represents the set of integers modulo q, and q is the order of the ellipse. Calculate PK TA =SK TA ·P as the institutional public key, and set the one-way hash functions and
[0042] After the initialization is completed, the trusted center saves the institutional private key SK TA , and publishes the institutional parameters parames = {p, q, E, P, G, PK TA , h1, h2}.
[0043] In the registration phase, the trusted center TA will register the roadside units RSU and vehicles V i entering the range of the RSU in the system. This process is carried out in real time, that is, new roadside units or vehicles can be registered in real time;
[0044] The registration process of the roadside unit is as follows:
[0045] Receive the unique identifier ID RSi generated by the roadside unit through the trusted center, and check whether the unique identifier ID RSi has been registered. If so, discard the registration request. Otherwise, receive and generate a random number as the roadside unit private key, calculate PK RSi =SK RSi ·P as the roadside unit public key, generate the registration signature Sign TA (ID RSi , PK RSi ), and send <Sign TA , SKRSi > Send it to the roadside unit applying for registration through a secure channel, Sign TA That is Sign TA (ID RSi , PK RSi );
[0046] After successful registration, the roadside unit saves the private key SK of the roadside unit RSi , and regularly broadcasts the public key PK of the roadside unit RSi , so that vehicles within the range can obtain its public key for communication. Figure 4 It is a schematic diagram of the roadside unit registration in the embodiment of the present invention, as Figure 4 shown, showing the interaction between the roadside unit and the trusted center authorization agency.
[0047] The vehicle registration process is as follows:
[0048] Generate a unique identifier ID through the vehicle Vi and combine it with the password PW set by the user Vi to activate the vehicle and generate a random number as the private key of the vehicle, and calculate PK Vi = SK Vi ·P as the public key of the vehicle, and send <ID Vi , PK Vi , T r > to the trusted center through a secure channel, where T r represents the registration application timestamp;
[0049] After receiving <ID Vi , PK Vi , T r > by the trusted center, detect and check whether the unique identifier ID Vi has been registered or revoked, and whether the registration application timestamp is within the first preset range, that is, detect the freshness of T r . If it has been registered, appears in the vehicle revocation list, or the freshness does not meet the requirements, any one of them is considered a failed inspection, and the registration request is discarded. Otherwise, receive the request to generate the vehicle verification parameter MerKle roor = h1(ID vi ||PK Vi ||T r ) and generate a block to be packed into the blockchain network, and send the block index BI Vi to the vehicle through a secure channel;
[0050] After successful registration, the vehicle generates a random number again and calculates the parameters and C i = h2(IDVi ||p i ||PW Vi ), then the vehicle publishes its own vehicle public key PK Vi , and i ,B i ,C i ,h1(SK Vi ||p i ),BI Vi >Stored in the vehicle trusted platform database TPD, h1(SK Vi ||p i ) can be used as a key management mechanism, Figure 5 Schematic diagram of vehicle information registration according to an embodiment of the present invention. Figure 5 As shown, the process of interaction between the vehicle and the trusted central authority and uploading blocks to generate indexes is demonstrated.
[0051] As a semi-trusted organization, the roadside unit needs a trusted center to generate a public-private key pair for it. As a mobile node, the vehicle autonomously generates a public-private key pair to ensure the privacy of its identity and communication efficiency, which is more in line with large-scale vehicle self-organizing networks.
[0052] In step S120, when a vehicle enters the range managed by a roadside unit, a vehicle pseudonym is generated, the vehicle pseudonym is received by the roadside unit, and the vehicle identity is preliminarily authenticated based on the vehicle verification parameters stored in the blockchain network, specifically including:
[0053] It should be noted that whenever the vehicle V i Entering into a new RSU i When within the jurisdiction, the vehicle pseudonym needs to be regenerated as a pseudo-identity to ensure the anonymity of the vehicle identity at different times and places. Even if multiple pseudonyms are intercepted, they cannot be associated with the real identity of the same vehicle, effectively protecting the privacy of the vehicle.
[0054] Before the vehicle pseudonym is generated, a legality verification is required. The vehicle-mounted unit in the vehicle receives the password PW′ entered by the user. Vi , calculate the parameters through the on-board unit OBU and Judge C′ i With C i Whether they are equal, if they are not equal, the legality verification fails, and if they are equal, the legality verification succeeds;
[0055] After the legality check is successful, a random number is generated by the vehicle Calculate K i =k i P, calculate K ij =k i ·PK RSi =(Kx , K y ), as a security verification parameter, calculate As the vehicle pseudonym, calculate The vehicle will <K i , L i , PID Vi , PK Vi , T k > is sent to the roadside unit through a secure channel, where T k represents the pseudonym generation timestamp;
[0056] The roadside unit starts the preliminary authentication V2I, checks whether the pseudonym generation timestamp is within the second preset range, that is, checks the freshness of the pseudonym generation timestamp. If it is not within the range, the preliminary authentication request is discarded. Otherwise, receive and calculate K' ij = K i ·SK RSi = (K' x , K' y ), and If the generated index BI' Vi belongs to the blockchain network, and △T = T k - T r is within the third preset range, calculate MerKle' root = h1(ID' vi || PK Vi || T r ), if MerKle' root is equal to the vehicle verification parameter MerKle root then the preliminary authentication is successful, otherwise the preliminary authentication fails;
[0057] The preliminary authentication ensures that the authenticated vehicle is a legal vehicle that has been registered within a reasonable time, Figure 6 is a schematic diagram of the pseudonym generation and preliminary authentication of the embodiments of the present invention, as Figure 6 shown, showing the complete preliminary authentication process including the legality verification.
[0058] In step S130, when the vehicle after preliminary authentication needs to transmit a message, generate a temporary key pair with an inverse operation using an optimized digital signature algorithm, generate a vehicle message signature based on the temporary key pair, and send the vehicle message signature to the corresponding roadside unit, specifically including:
[0059] When vehicle V i needs to transmit a message to surrounding vehicles or the roadside unit, in order to ensure the integrity and verifiability of the vehicle message, the vehicle needs to sign the message and then by the affiliated RSU iVerification is performed. Step S130 describes the message signature phase, and step S140 describes the verification phase;
[0060] In the embodiment of the present invention, an optimized Elliptic Curve Digital Signature Algorithm (ECDSA) is used to generate a temporary key pair:
[0061] The vehicle generates a random number as the temporary private key, and calculates tp i = ts i -1 ·P as the temporary public key; and a random number is generated Calculate X i = d i ·P = (X x , X y ), calculate R i = X x (mod q);
[0062] Convert the message m i to an integer M i = h2(m i ), calculate the signature verification parameter O i = h2(M i ||BI Vi ||ID Vi ||T s ), where T s represents the message signature timestamp, calculate the signature S i = ts i (d i - M i )(mod q) and generate the signature Sign i of the message m Vi = (R i , S i ), and send the complete vehicle message signature <Sign Vi = (R i , S i ), V i , m i , T s > to the corresponding roadside unit, where V i represents vehicle i.
[0063] In the traditional ECDSA algorithm, the public key is calculated as tp i = ts i ·P, multiplying the private key by the generator P. However, in the embodiment of the present invention, the key pair generation method is changed to directly store the pre-computed inverse of the temporary pre-processing value, and only one inverse operation is required to eliminate the more complex modular inverse operation during signature generation and subsequent signature verification. The modular inverse operation has a larger computational complexity compared to the inverse operation or normal modular operation.
[0064] In step S140, the roadside unit continuously receives vehicle message signatures and performs signature authentication on the vehicle message signatures using single or batch processing methods. After successful signature authentication, message transmission is allowed, specifically including:
[0065] The roadside unit continuously receives vehicle message signatures <Sign Vi =(R i , S i ), V i , m i , T s >;
[0066] If the roadside unit receives a single vehicle message signature, the single processing method is used:
[0067] Check whether the message signature timestamp is within the fourth preset range, that is, check the freshness of the message time signature. If it is not within the range, discard the vehicle message signature;
[0068] Calculate M' i =h2(m i ) and O' i =h2(M' i ||BI' Vi ||ID' Vi ||T s ). If O' i is not equal to the signature verification parameter O i , directly discard it. Otherwise, continue to verify and calculate U1 = S i (mod q), U2 = M' i (mod q), and here O i has been verified. M' i in the calculation of U2 is M i , X' i =U1·tp i +U2·P = (X' x , X' y ) and R' i =X' x (mod q); if R' i is not equal to R i , the signature authentication conclusion is invalid, otherwise it is valid; due to the use of the optimized ECDSA algorithm, no complex modular inverse operation is required at this stage;
[0069] In the vehicle-to-everything (V2X) network, it is often the case that multiple vehicles send messages within a short period of time. Therefore, to reduce latency and improve efficiency, if the roadside unit receives more than one vehicle message signature within the preset time, the batch processing method is used:
[0070] Check whether the message signature timestamp is within the fourth preset range, and eliminate the vehicle message signatures that are not within the range to obtain a message set;
[0071] Calculate and Aggregate the signatures in the message set to obtain an aggregated signature Sign agg =(R agg , S agg ), calculate Aggregate the hash values in the message set, calculate U 1agg =S agg (mod q) and U 2agg =M agg (mod q) aggregate the verification parameters, calculate Aggregate the temporary public keys, where n represents the aggregation quantity;
[0072] Calculate X agg =U 1agg ·tp agg +U 2agg ·P=(x xagg , x yagg ), if x xagg (mod q) is not equal to R agg , then all signature authentication conclusions in the message set are invalid, and all message segments are rejected; otherwise, all signatures are received and transmission is allowed.
[0073] In step S150, the roadside unit detects malicious vehicles and revokes their registrations, specifically including:
[0074] The roadside unit uses common technical means in the field to track the vehicles with malicious identities and those that publish false messages;
[0075] When the roadside unit detects a malicious vehicle, based on the vehicle pseudonym PID vi and K i , and the roadside unit private key SK RSi to deduce the vehicle unique identifier ID Vi ,
[0076] The value is 1, and ID Vi can be simplified and restored;
[0077] After deducing the unique identifier ID Vi of the malicious vehicle, revoke the block h1(ID Vi ||PK Vi ) stored in the blockchain network, and add the malicious vehicle information to the vehicle revocation list and send it to the trusted center. In the future, in the V2I preliminary authentication, the RSUi Fail to pass BI Vi Legal information for malicious vehicle registration cannot be retrieved through BI. The malicious vehicle cannot communicate normally with other vehicles or roadside units. Even if it submits a registration request to the trusted center again, it can be found that it has been revoked before, and the registration request of the malicious vehicle is rejected.
[0078] The above technical solutions of the embodiments of the present invention will be illustrated with reference to the following drawings.
[0079] In summary, in view of the existing problems, the vehicle-mounted network identity authentication method of the present invention adopts a decentralized identity authentication management solution. The trusted center and roadside units jointly maintain blockchain nodes, effectively avoiding single-point failures and ensuring the immutability and traceability of data. The dynamic pseudonym mechanism generates new pseudonym information each time a vehicle enters the range of a roadside unit, ensuring that the vehicle uses different identity identifiers at different times and locations, and protecting privacy and unlinkability. The digital signature algorithm is optimized to generate a temporary key pair with an inverse operation added, eliminating the complex modular inverse operation in signature generation and verification of traditional algorithms, and significantly reducing the computational overhead. When the roadside unit detects malicious behavior, it can quickly deduce the real identity of the vehicle and complete the revocation work on the blockchain, ensuring that malicious vehicles cannot register or participate in communication again.
[0080] Device Embodiment
[0081] According to an embodiment of the present invention, a vehicle-mounted network identity authentication device is provided. The device is applied to a consortium blockchain composed of a trusted center, roadside units, and a blockchain network. Figure 7 It is a schematic diagram of the vehicle-mounted network identity authentication device according to an embodiment of the present invention. As Figure 7 shown, the vehicle-mounted network identity authentication device according to an embodiment of the present invention specifically includes:
[0082] An initialization module 70, configured to initialize the trusted center, register roadside unit and vehicle information, and store the verified parameters of the registered vehicles in the blockchain network. Specifically, it is used for:
[0083] Initializing the trusted center specifically includes:
[0084] Randomly generate two prime numbers p and q by the trusted center, define an elliptic curve Ε: y 2 = x 3 + ax + b (mod p) in a finite field, generate a cyclic additive group G of order prime number q based on prime number p, and obtain a generator P of the cyclic additive group G. Among them, the condition in the cyclic additive group G is 4a 3 + 27b 2 (mod p) ≠ 0;
[0085] Generate a random number by the trusted center As the institutional private key, where represents the set of integers modulo q, calculate PK TA = SK TA ·P as the institutional public key, set the one-way hash function and
[0086] After the initialization is completed, the trusted center saves the institutional private key SK TA , and publishes the institutional parameters parames = {p, q, E, P, G, PK TA , h1, h2}.
[0087] Receive the unique identifier ID generated by the roadside unit through the trusted center RSi , check whether the unique identifier ID RSi has been registered. If so, discard the registration request. Otherwise, receive and generate a random number as the roadside unit private key, calculate PK RSi = SK RSi ·P as the roadside unit public key, generate the registration signature Sign TA (ID RSi , PK RSi ), and send <Sign TA , SK RSi > to the roadside unit applying for registration through a secure channel;
[0088] After successful registration, the roadside unit saves the roadside unit private key SK RSi , and periodically broadcasts the roadside unit public key PK RSi ;
[0089] Generate a unique identifier ID through the vehicle Vi and combine it with the password PW set by the user Vi to activate the vehicle, generate a random number as the vehicle private key, calculate PK Vi = SK Vi ·P as the vehicle public key, and send <ID Vi , PK Vi , T r > to the trusted center through a secure channel, where T r represents the registration application timestamp;
[0090] Detect and check whether the unique identifier ID Vi has been registered or revoked through the trusted center, and whether the registration application timestamp is within the first preset range. If the verification fails, discard the registration request. Otherwise, generate the vehicle verification parameter MerKle root = h1(ID Vi || PK Vi || Tr ) and generate a block to be packed into the blockchain network, and send the block index BI Vi to the vehicle through a secure channel;
[0091] After successful registration, the vehicle generates a random number Calculate and C i = h2(ID Vi ||p i ||PW Vi ), and publish the vehicle public key PK vi and store <A i , B i , C i , h1(SK Vi ||p i ), BI vi > in the vehicle trusted platform database.
[0092] The preliminary authentication module 72 is used to generate a vehicle pseudonym when the vehicle enters the range managed by a certain roadside unit, receive the vehicle pseudonym through the roadside unit, and perform preliminary authentication on the vehicle identity based on the vehicle verification parameters stored in the blockchain network. Specifically, it is used for:
[0093] Perform a legality verification before generating the vehicle pseudonym. The on-vehicle unit in the vehicle receives the password PW' Vi input by the user, calculate the parameters and Judge whether C' i is equal to C i . If not, the legality verification fails;
[0094] After the legality verification is successful, the vehicle generates a random number Calculate K i = k i ·P, calculate K ij = k i ·PK RSi = (K x , K y ) as the security verification parameter, calculate as the vehicle pseudonym, calculate The vehicle sends <K i , L i , PID Vi , PK Vi , T k > to the roadside unit through a secure channel, where T k represents the pseudonym generation timestamp;
[0095] Initiate preliminary authentication through the roadside unit, check whether the pseudonym generation timestamp is within the second preset range. If it is not within the range, discard the preliminary authentication request; otherwise, calculate K′ ij = K i ·SK RSi = (K′ x , K′ y ), and If the generated index BI′ Vi belongs to the blockchain network and △T = T k - T r is within the third preset range, calculate MerKle′ root = h1(ID′ Vi || PK Vi || T r ). If MerKle′ root is equal to the vehicle verification parameter MerKle root , the preliminary authentication is successful.
[0096] The message signature module 74 is used to generate a temporary key pair with inverse operation using an optimized digital signature algorithm when the vehicle after preliminary authentication needs to transmit a message, generate a vehicle message signature based on the temporary key pair, and send the vehicle message signature to the corresponding roadside unit. Specifically, it is used for:
[0097] Generate a temporary key pair using the optimized elliptic curve digital signature algorithm, generate a random number by the vehicle as the temporary private key, calculate tp i = ts i -1 ·P as the temporary public key; and generate a random number Calculate X i = d i ·P = (X x , X y ), calculate R i = X x (mod q);
[0098] Convert the message m i to an integer M i = h2(m i ), calculate the signature verification parameter O i = h2(M i || BI Vi || ID Vi || T s ), where T s represents the message signature timestamp, calculate the signature S i = ts i (d i - Mi )(mod q) and generate message m i Sign Vi =(R i ,S i ), sign the complete vehicle message <Sign Vi =(R i ,S i ),V i ,m i ,T s >Sent to the corresponding roadside unit, where V i Represents vehicle i.
[0099] The signature authentication module 76 is used to continuously receive vehicle message signatures through the roadside unit, perform signature authentication on the vehicle message signatures using a single or batch processing method, and allow message transmission after successful signature authentication, specifically for:
[0100] If the roadside unit receives a single vehicle message signature, a single processing method is used:
[0101] Check whether the message signature timestamp is within a fourth preset range, and if not, discard the vehicle message signature;
[0102] Calculate M′ i =h2(m i ) and o′ i =h2(M′ i ||BI′ Vi ||ID′ Vi ||T s ), if o′ i With signature verification parameter O i If they are not equal, discard them directly, otherwise continue to verify and calculate U1=S i (mod q), U2=M′ i (mod q), X′ i =U1·tp i +U2·P=(X′ x ,X′ y ) and R′ i =X′ x (mod q); if R′ i With R i If they are not equal, the signature authentication conclusion is invalid;
[0103] If the RSU receives more than one vehicle message signature within a preset time, batch processing is used:
[0104] Check whether the message signature timestamp is within a fourth preset range, and remove vehicle message signatures that are not within the range to obtain a message set;
[0105] Calculate and Aggregate the signatures in the message set to obtain the aggregated signature Sign agg =(R agg , S agg ), calculate Aggregate the hash values in the message set, calculate U 1agg =S agg (mod q) and U 2agg =M agg (mod q) aggregate the verification parameters, calculate Aggregate the ephemeral public keys;
[0106] Calculate X agg =U 1agg ·tp agg +U 2agg ·P=(x xagg , x yagg ), if x xagg (mod q) is not equal to R agg , all the signature authentication conclusions in the message set are invalid.
[0107] The vehicle revocation module 78 is used to detect malicious vehicles through the roadside unit and revoke their registrations, specifically for:
[0108] When the roadside unit detects a malicious vehicle, according to the vehicle pseudonym PID Vi and K i , and the roadside unit private key SK RSi deduce the vehicle unique identifier ID Vi ,
[0109] After deducing the unique identifier ID Vi of the malicious vehicle, revoke the block h1(ID Vi ||PK Vi ) stored in the blockchain network, and add the malicious vehicle information to the vehicle revocation list and send it to the trusted center.
[0110] In summary, in view of the existing problems in the current situation, the in-vehicle network identity authentication device of the present invention adopts a decentralized identity authentication management scheme. The blockchain nodes are jointly maintained by a trusted center and roadside units, effectively avoiding single-point failures and ensuring the immutability and traceability of data. A dynamic pseudonym mechanism is adopted to generate new pseudonym information every time a vehicle enters the range of a roadside unit, ensuring that the vehicle uses different identity identifiers at different times and locations, and protecting privacy and non-linkability. The digital signature algorithm is optimized to generate a temporary key pair with an inverse operation added, eliminating the complex modular inverse operation in signature generation and verification of traditional algorithms, and significantly reducing the computational overhead. When a roadside unit detects malicious behavior, it can quickly reverse the true identity of the vehicle and complete the revocation work on the blockchain, ensuring that malicious vehicles cannot register or participate in communication again.
[0111] Embodiment of Electronic Device
[0112] Figure 8 FIG. is a schematic diagram of an electronic device according to an embodiment of the present invention. The electronic device 800 may include at least one processor 810 and a memory 820. The processor 810 may execute instructions stored in the memory 820. The processor 810 is communicatively connected to the memory 820 via a data bus. In addition to the memory 820, the processor 810 may also be communicatively connected to an input device 830, an output device 840, and a communication device 850 via the data bus.
[0113] The processor 810 may be any conventional processor, such as a commercially available CPU. The processor may also include, for example, a Graphic Process Unit (GPU), a Field Programmable Gate Array (FPGA), a System on Chip (SOC), an Application Specific Integrated Circuit (ASIC), or a combination thereof.
[0114] The memory 820 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.
[0115] In an embodiment of the present disclosure, executable instructions are stored in the memory 820. The processor 810 may read the executable instructions from the memory 820 and execute the instructions to implement all or part of the steps of the in-vehicle network identity authentication method in any of the above exemplary embodiments.
[0116] Example of computer-readable storage medium
[0117] In addition to the above methods and devices, an exemplary embodiment of the present disclosure may also be a computer program product or a computer-readable storage medium storing the computer program product. The computer product includes computer program instructions that can be executed by a processor to implement all or part of the steps described in any one of the on-vehicle network identity authentication methods in the above exemplary embodiments.
[0118] The computer program product can be written in any combination of one or more programming languages for the program code to perform the operations of the embodiments of the present application. The programming languages include object-oriented programming languages such as Java and C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages, as well as scripting languages (such as Python). The program code can be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0119] The computer-readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of the readable storage medium include: static random access memory (SRAM) with one or more wire electrical connections, electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disk, or any suitable combination of the above.
[0120] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A vehicle-mounted network identity authentication method, characterized in that, The method is applied to a consortium chain consisting of a trusted center, a roadside unit and a blockchain network, including: Initialize the trusted center, register the roadside unit and vehicle information, and store the successfully registered vehicle verification parameters in the blockchain network; When a vehicle enters a range managed by a roadside unit, a vehicle pseudonym is generated, the vehicle pseudonym is received by the roadside unit, and a preliminary authentication of the vehicle identity is performed based on the vehicle verification parameters stored in the blockchain network; When a vehicle that has undergone preliminary authentication needs to transmit a message, an optimized digital signature algorithm is used to generate a temporary key pair with an inverse operation added, a vehicle message signature is generated based on the temporary key pair, and the vehicle message signature is sent to the corresponding roadside unit; Continuously receiving the vehicle message signature by the roadside unit, performing signature authentication on the vehicle message signature in a single or batch processing manner, and allowing message transmission after successful signature authentication; Malicious vehicles are detected and their registration is deregistered through the roadside unit.
2. The method according to claim 1, wherein The initialization of the trusted center specifically includes: Randomly generate two prime numbers p and q through a trusted center, and define an elliptic curve Ε in a finite field: y 2 = x 3 + ax + b (mod p), generate a cyclic additive group G of prime order q based on the prime number p, and obtain a generator P of the cyclic additive group G, where the condition in the cyclic additive group G is 4a 3 + 27b 2 (mod p) ≠ 0; Generate a random number through a trusted center As the institutional private key, where Denotes the set of integers modulo q, calculate PK TA = SK TA ·P as the institutional public key, set the one-way hash functions h1: And h2: After the initialization is completed, the trusted center saves the institutional private key SK TA , and publishes the institutional parameters parames = {p, q, E, P, G, PK TA , h1, h2}.
3. The method according to claim 2, wherein The registering of the roadside unit and vehicle information and storing the successfully registered vehicle verification parameters in the blockchain network specifically include: Receive the unique identification ID generated by the roadside unit through the trusted center RSi , check the unique identification ID RSi Whether it is registered. If it is, the registration request is lost. Otherwise, receive and generate a random number As the private key of the roadside unit, calculate PK RSi = SK RSi ·P as the public key of the roadside unit, generate the registration signature Sign TA (ID RSi , PK RSi ), and send <Sign TA , SK RSi > to the roadside unit applying for registration through the secure channel; After successful registration, the roadside unit saves the private key SK of the roadside unit RSi , and regularly broadcasts the public key PK of the roadside unit RSi ; Generate a unique identification ID for the vehicle Vi And combine with the password PW set by the user Vi Activate the vehicle and generate a random number As the vehicle private key, calculate PK Vi =SK Vi ·P as the vehicle public key, send <ID Vi , PK Vi , T r > to the trusted center through the secure channel, where T r represents the registration application timestamp; Check the unique identification ID through the trusted center detection Vi Whether it has been registered or revoked, and whether the registration application timestamp is within the first preset range. If the verification fails, discard the registration request; otherwise, generate the vehicle verification parameter MerKle root = h1(ID Vi || PK Vi || T r ) and generate a block to be packaged into the blockchain network, and send the block index BI Vi To the vehicle through a secure channel; After successful registration, the vehicle generates a random number Calculate and C i = h2(ID Vi || p i || PW Vi ), and disclose the vehicle public key PK Vi and store <A i , B i , C i , h1(SK Vi || p i ), BI Vi > in the vehicle trusted platform database.
4. The method according to claim 3, characterized in that, The generating of a vehicle pseudonym when a vehicle enters a range managed by a roadside unit, receiving the vehicle pseudonym through the roadside unit, and performing preliminary authentication of the vehicle identity based on the vehicle verification parameters stored in the blockchain network specifically includes: Before generating the vehicle kana, perform a legality verification. The in-vehicle unit in the vehicle receives the password PW' input by the user Vi , calculate the parameter and judge C' i and C i Whether they are equal. If not, the legality verification fails; Generate a random number through the vehicle after successful legality verification Calculate K i = k i ·P, calculate K ij = k i ·PK RSi =(K x , K y ) as the security verification parameter, calculate as the vehicle pseudonym, calculate The vehicle will send <K i , L i , PID Vi , PK Vi , T k > to the roadside unit through the secure channel, where T k represents the pseudonym generation timestamp; Initiate preliminary authentication through the roadside unit, check whether the pseudonym generation timestamp is within the second preset range. If it is not within the range, discard the preliminary authentication request; otherwise, calculate K′ ij = K i ·SK RSi = (K′ x , K′ y ), and If the generated index BI′ Vi belongs to the blockchain network and △T = T k - T r is within the third preset range, calculate MerKle′ root = h1(ID′ Vi || PK Vi || T r ). If MerKle′ root is equal to the vehicle verification parameter MerKle root , the preliminary authentication is successful.
5. The method according to claim 4, characterized in that, The step of using an optimized digital signature algorithm to generate a temporary key pair with an inverse operation added thereto, generating a vehicle message signature based on the temporary key pair, and sending the vehicle message signature to a corresponding roadside unit specifically includes: Generate a temporary key pair using an optimized elliptic curve digital signature algorithm and generate a random number by the vehicle As the temporary private key, calculate tp i = ts i -1 ·P as the temporary public key; and generate a random number Calculate X i = d i ·P = (X x , X y ), calculate R i = X x (mod q); Convert the message m i to an integer M i = h2(m i ), calculate the signature verification parameter O i = h2(M i ||BI Vi ||ID Vi ||T s ), where T s represents the signature timestamp of the sent message, calculate the signature S i = ts i (d i - M i )(mod q) and generate the signature Sign i of the message m Vi = (R i , S i ), send the complete vehicle message signature <Sign Vi = (R i , S i ), V i , m i , T s > to the corresponding roadside unit, where V i represents vehicle i.
6. The method according to claim 5, characterized in that, The step of continuously receiving the vehicle message signature by the roadside unit and performing signature authentication on the vehicle message signature in a single or batch processing manner specifically includes: If the roadside unit receives a single vehicle message signature, a single processing method is used: Check whether the message signature timestamp is within a fourth preset range, and if not, discard the vehicle message signature; Calculate M′ i = h2(m i ) and O′ i = h2(M′ i ||BI′ Vi ||ID′ Vi ||T s ), if O′ i is not equal to the signature verification parameter O i , then directly discard it, otherwise continue to verify and calculate U1 = S i (mod q), U2 = M′ i (mod q), X′ i = U1·tp i + U2·P = (X′ x , X′ y ) and R′ i = X′ x (mod q); if R′ i is not equal to R i , then the signature authentication conclusion is invalid; If the RSU receives more than one vehicle message signature within a preset time, batch processing is used: Check whether the message signature timestamp is within a fourth preset range, and remove vehicle message signatures that are not within the range to obtain a message set; Calculate and Aggregate the signatures in the message set to obtain the aggregated signature Sign agg =(R agg , S agg ), calculate Aggregate the hash values in the message set, calculate U 1agg =S agg (mod q) and U 2agg =M agg (mod q) aggregate the verification parameters, calculate Aggregate the temporary public keys, where n represents the aggregation quantity; Calculate X agg = U 1agg ·tp agg + U 2agg ·P = (x xagg , x yagg ), if x xagg (mod q) is not equal to R agg then all signature authentication conclusions in the message set are invalid.
7. The method according to claim 6, wherein The detecting a malicious vehicle by the roadside unit and cancelling its registration specifically includes: After the roadside unit detects a malicious vehicle, according to the vehicle pseudonym PID Vi and K i , and the roadside unit private key SK RSi deduce the vehicle unique identifier ID Vi , Deduce and obtain the unique identification ID of the malicious vehicle Vi After that, revoke the block h1 (ID Vi ||PK Vi ) stored in the blockchain network, and add the malicious vehicle information to the vehicle revocation list and send it to the trusted center.
8. An in-vehicle network identity authentication device, characterized in that The device is applied to a consortium chain consisting of a trusted center, a roadside unit and a blockchain network, including: An initialization module, used to initialize the trusted center, register the roadside unit and vehicle information, and store the verification parameters of the successfully registered vehicle in the blockchain network; A preliminary authentication module, configured to generate a vehicle pseudonym when a vehicle enters a range managed by a roadside unit, receive the vehicle pseudonym through the roadside unit, and perform preliminary authentication on the vehicle identity based on vehicle verification parameters stored in the blockchain network; A message signature module is used to generate a temporary key pair with an inverse operation using an optimized digital signature algorithm when a vehicle that has passed preliminary authentication needs to transmit a message, generate a vehicle message signature based on the temporary key pair, and send the vehicle message signature to a corresponding roadside unit; Signature authentication module, which is used to continuously receive the vehicle message signature through the roadside unit, perform signature authentication on the vehicle message signature in a single or batch processing manner, and allow message transmission after successful signature authentication; Vehicle revocation module, which is used to detect malicious vehicles through the roadside unit and revoke their registrations.
9. An electronic device, characterized in that, Comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the vehicle network identity authentication method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, characterized in that, An implementation program for information transmission is stored on the computer-readable storage medium. When the program is executed by the processor, the steps of the vehicle network identity authentication method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Identity authentication method and system for resisting identity forgery attack
CN120750593A