Internet of vehicles certificateless condition privacy protection method based on self-adaptive signature and signcryption

By combining the certificate-free signature and signature mechanism, a certificate-free privacy protection method for adaptive selection of signature and signature is designed, which solves the problem of high computing and communication overhead in the Internet of Vehicles, and achieves efficient privacy protection and security authentication.

CN120302283AActive Publication Date: 2025-07-11YANTAI UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510605423.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-11
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

The existing privacy protection solution without certificates cannot adaptively select the signature or signature mechanism in the Internet of Vehicles, resulting in too high computing and communication overhead and unable to effectively protect the privacy information of connected vehicles.

Method used

Combining the certificate-free signature mechanism and the signature mechanism, a certificate-free privacy protection method is designed to adaptively select signatures and signatures. The pseudo-identity and partial private keys are generated through KGC, the elliptic curve algorithm is used to generate public and private keys, and information tuples are generated through the adaptive signature and signature algorithm to achieve the flexibility and efficiency of message authentication.

Benefits of technology

It reduces computing and communication overhead, improves the efficiency and security of message authentication, effectively protects the privacy information of connected vehicles, and adapts to the privacy needs of different messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302283A_ABST
    Figure CN120302283A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network connection automobile safety communication, and particularly relates to an adaptive signature and signcryption vehicle networking certificateless condition privacy protection method comprising the following steps: initializing vehicle networking system parameters; the KGC generates a pseudo identity and a part of private keys corresponding to the networked automobile according to identity information submitted by the registered networked automobile, and sends the pseudo identity and the part of private keys to the networked automobile terminal through the secure channel; the networked automobile terminal generates a private key and a public key based on the received pseudo identity, partial private key and system parameters; the first networked automobile generates a message tuple by adopting an adaptive signature and signcryption algorithm based on the to-be-sent information, the privacy demand, the public key of the second networked automobile and the system parameters, and sends the message tuple to the second networked automobile; and after receiving the message tuple, the second networked automobile executes a signature and signcryption verification algorithm according to the private key of the message tuple, the system parameters and the public key of the first networked automobile, original information is recovered, the correctness of the original information is verified, and efficient message authentication of the Internet of Vehicles is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of secure communication of connected vehicles, and particularly relates to a certificateless conditional privacy protection method for vehicle-to-everything (V2X) with adaptive signature and signcryption. Background Art

[0002] In vehicle-to-everything (V2X), connected vehicles improve traffic efficiency and traffic safety by broadcasting basic safety messages. However, this cleartext broadcasting method enables attackers to obtain privacy information such as the location and driving trajectory of connected vehicles through the open wireless communication channel, thereby causing the privacy leakage of users. Currently, certificateless conditional privacy protection schemes are applied to message authentication in vehicle-to-everything (V2X) because they solve the problems of certificate management and key escrow. However, the certificateless conditional privacy protection scheme relies on a single signature mechanism or signcryption mechanism, and does not fully consider that the basic safety message contains both privacy and non-privacy information, and cannot adaptively select the signature or signcryption mechanism according to the privacy requirements of the message.

[0003] In addition, when ensuring security, existing certificateless conditional privacy protection schemes based on signature mechanisms or signcryption mechanisms often come at the cost of sacrificing computational overhead or increasing communication overhead. Due to the limited computational and storage resources of in-vehicle units and the limitation of communication bandwidth, the performance of message authentication is as important as security and privacy protection. Therefore, in order to provide a secure, efficient and conditional privacy protection message authentication scheme for connected vehicle communication, it is necessary to design a certificateless conditional privacy protection scheme that can adaptively select signature and signcryption and reduce computational overhead and communication overhead. Summary of the Invention

[0004] To solve the problems existing in the existing certificateless conditional privacy protection scheme, such as the inability to dynamically select the signature or signcryption mechanism and the low efficiency of message authentication, the present invention combines the certificateless signature mechanism and the certificateless signcryption mechanism, ensures the high efficiency and security of communication, and integrates the signature and signcryption mechanisms into a parallel algorithm in the communication network between connected vehicles, greatly improving the flexibility of message authentication.

[0005] A certificateless conditional privacy protection method for vehicle-to-everything (V2X) with adaptive signature and signcryption includes:

[0006] The KGC initializes the vehicle-to-everything (V2X) system parameters based on system security parameters;

[0007] The KGC generates a pseudo-identity and a partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, and sends the generated pseudo-identity and partial private key to the corresponding connected vehicle;

[0008] Based on a pseudo-identity, partial private key, and system parameters, the connected vehicle generates its private key and public key, and uploads the public key to the KGC. The KGC updates the connected vehicle pseudo-identity - public key mapping list and distributes it to all connected vehicles within the region.

[0009] The first connected vehicle obtains the connected vehicle message to be sent, determines that the receiving connected vehicle of the message is the second connected vehicle, and retrieves the corresponding public key from the connected vehicle pseudo-identity - public key mapping list according to the pseudo-identity of the second connected vehicle.

[0010] Based on its own private key, the connected vehicle message to be sent, the public key of the second connected vehicle, and system parameters, and according to the privacy requirements of the connected vehicle message, the first connected vehicle executes an adaptive signature and ciphertext algorithm to generate an information tuple, and sends the information tuple to the second connected vehicle.

[0011] After receiving the information tuple, the second connected vehicle compares the timeliness of the timestamp in the information tuple. If the timeliness is satisfied, it recovers the connected vehicle message, and uses the information tuple, the public key of the first connected vehicle, and system parameters to judge the correctness of the recovered connected vehicle message. Only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

[0012] Furthermore, the KGC initializes the vehicle networking system parameters based on system security parameters, including:

[0013] The KGC selects an elliptic curve E that satisfies the security parameter k, and generates partial parameters {P, q, G} of the system, where G is an additive cyclic group defined by the elliptic curve E, and P is a generator of the group G with order q, a prime number.

[0014] The KGC randomly selects a master key s from the multiplicative group of integers modulo q where and calculates the system's master public key based on the system's master key s and partial parameter P through elliptic curve scalar multiplication.

[0015] The KGC configures a first hash function H0, a second hash function H1, a third hash function H2, a fourth hash function H3, and a function F for adaptive selection of signature and ciphertext: a × {0, 1} → {0, a}; where, F(a, 0) = 0, F(a, 1) = a;

[0016] Based on the first hash function H0, the second hash function H1, the third hash function H2, the fourth hash function H3, partial parameters {P, q, G}, and the function F, the KGC generates a system parameter set sp = {G, P, q, P pub,F,H0,H1,H2,H3}。

[0017] Further, the KGC generates a pseudo - identity and a partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, including:

[0018] The connected vehicle selects a random value from the multiplicative group of integers modulo q and calculates partial identity information of the connected vehicle based on elliptic curve scalar multiplication operation; the connected vehicle sends the real identity and the partial identity information of the connected vehicle to the KGC through a secure channel;

[0019] The KGC obtains a pseudonym identifier and a pseudo - identity based on the received real identity of the connected vehicle, partial identity information, system master key, system public master key, fourth hash function, and first hash function through a pseudo - identity generation algorithm;

[0020] The KGC randomly selects a random value from the multiplicative group of integers modulo q and obtains a partial private key of the connected vehicle based on the random value, the public master key of the system, the second hash function, and the pseudo - identity through a partial private key generation algorithm.

[0021] Further, the connected vehicle generates a private key and a public key of the connected vehicle based on the pseudo - identity, partial private key, and system parameters, including:

[0022] The connected vehicle constructs a partial private key discriminant using elliptic curve scalar multiplication operation according to the pseudo - identity of the connected vehicle, the partial private key of the connected vehicle, and the system parameters. When and only when the partial private key discriminant holds, the connected vehicle accepts the pseudo - identity and the partial private key of the connected vehicle;

[0023] Once the partial private key discriminant holds, the connected vehicle selects a random number from the multiplicative group of integers modulo q and calculates the private key of the connected vehicle using the random number and the partial private key through a private key generation algorithm;

[0024] The connected vehicle calculates the public key of the connected vehicle using elliptic curve scalar multiplication operation according to the private key of the connected vehicle and the system parameters.

[0025] Further, the first connected vehicle executes an adaptive signature - encryption algorithm to generate an information tuple based on its own private key, the connected vehicle message to be sent, the public key of the second connected vehicle, and the system parameters according to the privacy requirements of the connected vehicle message, including:

[0026] The first connected vehicle obtains a random value from the multiplicative group of integers modulo q and generates a first information value using elliptic curve scalar multiplication operation according to the random value and the system parameters;

[0027] The first connected vehicle calculates a second hash value by invoking a second hash function according to the pseudo-identity of the first connected vehicle, the first information value, and the connected vehicle message to be sent.

[0028] The first connected vehicle obtains a second information value by performing modular multiplication on the private key of the first connected vehicle and the second hash value and then performing modular addition with the random value.

[0029] The first connected vehicle calculates a third hash value by invoking a fourth hash function based on the random value and the public key of the second vehicle, and performs an exclusive OR operation on the result of invoking the function function based on the third hash value and the message to be sent to obtain a third information value; an information tuple is generated according to the first information value, the second information value, the third information value, and the current timestamp.

[0030] Further, after receiving the information tuple, if the timeliness is satisfied, the second connected vehicle uses the signature and ciphertext verification algorithm to recover the connected vehicle message, including:

[0031] After receiving the information tuple, the second connected vehicle verifies the timeliness by comparing the difference between the timestamp in the information tuple and the current system time with a preset threshold: when the difference is less than or equal to the preset threshold, the second connected vehicle uses the signature and ciphertext verification algorithm to recover the connected vehicle message.

[0032] Further, using the signature and ciphertext verification algorithm to recover the connected vehicle message includes:

[0033] The second connected vehicle calculates a mapping value through elliptic curve scalar multiplication on the private key of the second connected vehicle and the first ciphertext, and calculates a fourth hash value by invoking the fourth hash function according to the mapping value.

[0034] The second connected vehicle performs an exclusive OR operation on the result of invoking the function F according to the fourth hash value and the third ciphertext to obtain the recovered connected vehicle message.

[0035] Further, using the information tuple, the public key of the first connected vehicle, and the system parameters to determine the correctness of the recovered connected vehicle message. When and only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message, including:

[0036] When the second connected vehicle only receives a group of information tuples; the second connected vehicle constructs a single-message discriminant through elliptic curve scalar multiplication according to the system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the recovered connected vehicle message is correct according to whether the single-message discriminant holds; when and only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

[0037] Further, using the information tuple, the public key of the first connected vehicle, and the system parameters to determine the correctness of the restored connected vehicle message. Only when the restored connected vehicle message is correct, the second connected vehicle receives the connected vehicle message, including:

[0038] When the second connected vehicle receives multiple groups of information tuples at the same time; the second connected vehicle constructs a batch discriminant through elliptic curve scalar multiplication operations according to the system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the restored connected vehicle message is correct according to whether the batch discriminant holds. Only when the restored connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

[0039] The present invention has at least the following beneficial effects compared with the prior art:

[0040] The present invention combines the certificateless signcryption mechanism and the certificateless signature mechanism, overcoming the technical defect that the existing certificateless conditional privacy protection scheme only adopts the signature or signcryption mechanism. Aiming at the limited computing and storage resources of the in-vehicle unit, this method designs a certificateless conditional privacy protection scheme for adaptive selection of signature and signcryption, realizing lightweight message authentication. The KGC uses OTA technology to dynamically maintain the mapping list of pseudo-identities and public keys of connected vehicles, and constructs a distributed storage among distributed connected vehicle nodes, which can effectively resist public key tampering attacks. On the premise of ensuring security and privacy protection, compared with the existing certificateless conditional privacy protection scheme, the present invention reduces the computational overhead and communication overhead, realizes an optimized balance of security, privacy protection, and message authentication efficiency, can meet the high-efficiency authentication requirements of in-vehicle units, and provides a reliable technical guarantee for the secure communication of intelligent transportation systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0042] Figure 1 is a flowchart of the present invention;

[0043] Figure 2 is a system model diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation manners, structures, features, and effects of the technical solutions proposed according to the present invention. The specific features, structures, or characteristics in one or more embodiments may be combined in any suitable form. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.

[0045] Please refer to Figure 1 - Figure 2 , the present invention provides a certificateless conditional privacy protection method for the Internet of Vehicles with adaptive signature and signcryption, including:

[0046] S1: The KGC initializes the Internet of Vehicles system parameters based on the system security parameters;

[0047] S2: The KGC generates the pseudo-identity and partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, and sends the generated pseudo-identity and partial private key to the corresponding connected vehicle;

[0048] S3: The connected vehicle generates the private key and public key of the connected vehicle based on the pseudo-identity, partial private key, and system parameters, and uploads the public key to the KGC. The KGC updates the connected vehicle pseudo-identity - public key mapping list and distributes it to all connected vehicles within the region;

[0049] S4: The first connected vehicle obtains the connected vehicle message to be sent, determines that the connected vehicle of the message recipient is the second connected vehicle, and retrieves the corresponding public key from the connected vehicle pseudo-identity - public key mapping list according to the pseudo-identity of the second connected vehicle;

[0050] S5: The first connected vehicle, based on its own private key, the connected vehicle message to be sent, the public key of the second connected vehicle, and the system parameters, executes the adaptive signature and signcryption algorithm according to the privacy requirements of the connected vehicle message to generate an information tuple, and sends the information tuple to the second connected vehicle;

[0051] S6: After receiving the information tuple, the second connected vehicle compares the timeliness of the timestamp in the information tuple. If the timeliness is satisfied, it restores the connected vehicle message, and uses the information tuple, the public key of the first connected vehicle, and the system parameters to judge the correctness of the restored connected vehicle message. Only when the restored connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

[0052] The following expands on each of the above steps in detail:

[0053] S1: The KGC initializes the Internet of Vehicles system parameters based on the system security parameters.

[0054] The KGC (Key Generation Center) generates the system parameters of the vehicle networking and publishes the system parameters and the list of vehicle networking pseudo-identity - public key mappings to the registered connected vehicles. As Figure 2 shown, the vehicle networking includes three entities: connected vehicles, roadside units, and the KGC. The KGC updates the list of vehicle networking pseudo-identity - public key mappings with the connected vehicles through OTA update technology.

[0055] The system parameters generated by the KGC for the vehicle networking include:

[0056] S11: The KGC selects an elliptic curve E that satisfies the security parameter k and generates partial parameters {p, q, G} of the system. Among them, G is an additive cyclic group defined by the elliptic curve E, and P is a generator of the group G with order prime number q;

[0057] S12: The KGC randomly selects the system master key s from the multiplicative group of integers modulo q where and calculates the system public master key P pub based on the system master key s and the partial parameter P through elliptic curve scalar multiplication operation, where P pub = sP;

[0058] S13: The KGC configures four cryptographic hash functions and an adaptive selection signature and signcryption functional function F: a × {0, 1} → {0, a}; where, F(a, 0) = 0, F(a, 1) = a;

[0059] The four cryptographic hash functions include the first hash function H0, the second hash function H1, the third hash function H2, and the fourth hash function H3, namely:

[0060] H0: {0, 1} π → G;

[0061]

[0062] H3: G → {0, 1} n ;

[0063] Among them, H0: {0, 1} π → G means that a string of length π bits is mapped to a point in the elliptic curve G; means that a point on the elliptic curve G is mapped to the value in ; means that a point on the elliptic curve G and a string of length n bits are mapped to the value in ; H3: G → {0, 1} n means that a point on the elliptic curve G is mapped to a string of length π bits.

[0064] The adaptive selection signature and signcryption functional function F: a × {0, 1} → {0, a} includes: when the information transmitted by the connected vehicle is non-private information such as the speed, gear state, heading angle, steering wheel angle, four-axis acceleration, and braking state of the connected vehicle, at this time b = 0, F(a, b) = 0; when the information transmitted by the connected vehicle is private information such as the position or historical trajectory of the connected vehicle, at this time b = 1, F(a, b) = a.

[0065] S14: Based on four hash functions, partial parameters {P, q, G}, and the functional function F, the KGC generates a system parameter set sp = {G, P, q, P pub , F, H0, H1, H2, H3} through the system parameter generation algorithm.

[0066] S2: The KGC generates the pseudo-identity and partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, and sends the generated pseudo-identity and partial private key to the corresponding connected vehicle.

[0067] The KGC generates the pseudo-identity and partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, including:

[0068] S21: The connected vehicle selects a random value from the multiplicative group of integers modulo q and calculates the partial identity information AID of the connected vehicle based on the elliptic curve scalar multiplication operation i,1 ; the connected vehicle sends the real identity ID i of the connected vehicle and the partial identity information AID i,1 to the KGC through a secure channel together;

[0069] The partial identity information AID i,1 of the connected vehicle includes:

[0070]

[0071] S22: The KGC obtains the pseudonym identifier PID i of the connected vehicle and the pseudo-identity AID i,1 of the connected vehicle through the pseudo-identity generation algorithm based on the received real identity ID pub of the connected vehicle, the partial identity information AID i of the connected vehicle, the system master key s, the system public key P i of the connected vehicle, the fourth hash function H3, and the first hash function H0;

[0072] The pseudonym identifier PID i of the connected vehicle includes:

[0073]

[0074] The pseudo-identity AID of the connected vehicle i includes:

[0075] AID i = H0(ID i ) + p i,1 ;

[0076] S23: KGC randomly selects a random number k from the multiplicative group of integers modulo q i , and based on this random number k i , the system master public key P pub , the second hash function H1, and the pseudo-identity AID of the connected vehicle i , obtains the partial private key of the connected vehicle through the partial private key generation algorithm;

[0077] The partial private key of the connected vehicle includes:

[0078] W i = k i P pub ;

[0079] h 1i = H1(AID i + W i );

[0080] p i = (k i + (s -1 h 1i mod q)) mod q;

[0081] where the partial private key of the connected vehicle V i is PSK i = {p i , W i}}. Among them, W i represents the first partial private key value of the connected vehicle V i , p i represents the second partial private key value of the connected vehicle V i , and h 1i represents the first hash value.

[0082] S3: The connected vehicle generates the private key and public key of the connected vehicle based on the pseudo-identity, partial private key, and system parameters; the connected vehicle uploads the pseudo-identity and public key to the KGC, and the KGC updates the connected vehicle pseudo-identity - public key mapping list and distributes it to all connected vehicles in this area.

[0083] The connected vehicle generates a private key and a public key of the connected vehicle based on a pseudo-identity, a partial private key, and system parameters, including:

[0084] S31: The connected vehicle constructs a partial private key discriminant using elliptic curve scalar multiplication according to the pseudo-identity, the partial private key, and the system parameters. The connected vehicle accepts the pseudo-identity and the partial private key of the connected vehicle if and only if the partial private key discriminant holds.

[0085] The partial private key discriminant includes:

[0086] p i P pub =W i +h 1i P;

[0087] where h 1i represents the first hash value calculated by the connected vehicle V i through h 1i =H1(AID i +W i ), W i represents the first partial private key value of the connected vehicle V i , and p i represents the second partial private key value of the connected vehicle V i .

[0088] S32: Once the partial private key discriminant holds, the connected vehicle selects a random number μ from the multiplicative group of integers modulo q i , and calculates the private key of the connected vehicle using the random number μ i and the partial private key of the connected vehicle through a private key generation algorithm;

[0089] The private key of the connected vehicle includes:

[0090] sk i =(μ i +p i ) mod q;

[0091] where sk i represents the private key of the connected vehicle V i , μ i represents a random number selected from , and p i represents the second partial private key value of the connected vehicle V i .

[0092] S33: The connected vehicle calculates the public key of the connected vehicle using elliptic curve scalar multiplication according to the private key of the connected vehicle and the system parameters.

[0093] The public key of the connected vehicle includes:

[0094] PK i = sk i P;

[0095] Among them, PK i represents the public key of the connected vehicle V i dk i represents the private key of the connected vehicle V i P represents the generator of the cyclic additive group G.

[0096] The connected vehicle pseudo-identity - public key mapping list is stored using a hash table data structure, where the pseudo-identity identifier is used as the key and the public key is used as the value.

[0097] The connected vehicle uploads its pseudo-identity and public key to the KGC through a secure channel, writes them into the connected vehicle pseudo-identity - public key mapping list, and uses the over-the-air (OTA) vehicle remote upgrade technology to send the updated connected vehicle pseudo-identity - public key mapping list to the on-vehicle units of all connected vehicles in this area.

[0098] S4: The first connected vehicle V i , obtains the connected vehicle message m to be sent i , determines that the connected vehicle of the message recipient is the second connected vehicle V j , retrieves the corresponding public key from the connected vehicle pseudo-identity - public key mapping list according to the pseudo-identity of the second connected vehicle.

[0099] All connected vehicles are connected vehicles in the vehicle network. The first connected vehicle is the message sender, and the second connected vehicle is the message recipient. Among them, the connected vehicle message includes: the information of the connected vehicle obtained by the connected vehicle through the electronic unit and the messages sent to the first connected vehicle by other connected vehicles or roadside units, etc.

[0100] S5: The first connected vehicle, based on its own private key, the connected vehicle message m to be sent i , the public key of the second connected vehicle, and the system parameters, executes the adaptive signature - encryption algorithm according to the privacy requirements of the connected vehicle message m i to generate an information tuple and send this information tuple to the second connected vehicle.

[0101] The first connected vehicle, based on its own private key, the connected vehicle message m to be sent i , the public key of the second connected vehicle, and the system parameters, executes the adaptive signature - encryption algorithm according to the privacy requirements of the connected vehicle message m i to generate an information tuple including:

[0102] S51: The first connected vehicle obtains a random value η from the multiplicative group of integers modulo q ​i , generate the first information value through elliptic curve scalar multiplication operation according to the random value η i and system parameters.

[0103] The first information value includes:

[0104] B i = η i P;

[0105] Among them, B i represents the first information value, η i represents a random number selected from .

[0106] S52: The first connected vehicle calculates the second hash value by invoking the second hash function H2 based on the pseudo - identity of the first connected vehicle, the first information value, and the connected vehicle message to be sent.

[0107] The second hash value includes:

[0108] h 2,i = H2((B i + ADI i ), m i );

[0109] Among them, h 2,i represents the second hash value, B i represents the first information value, AID i represents the pseudo - identity of the first connected vehicle, m i represents the connected vehicle message to be sent.

[0110] S53: The first connected vehicle obtains the second information value through modular addition of the modular multiplication of the private key of the first connected vehicle and the second hash value with the random number η i .

[0111] The second information value includes:

[0112] c 2,i = (η i +(h 2,i sk i ) mod q) mod q;

[0113] Among them, c 2,i represents the second information value, h 2,i represents the second hash value, η i represents a random number selected from , sk i represents the private key of the first connected vehicle V i , and q represents a large prime number.

[0114] S54: The first connected vehicle calculates the third hash value by invoking the fourth hash function H3 based on the random number η i and the public key of the second connected vehicle, and performs an exclusive OR operation with the message to be sent after invoking the functional function based on the third hash value to obtain the third information value; generates an information tuple according to the first information value, the second information value, the third information value, and the current timestamp.

[0115] The third hash value includes:

[0116] h 3,i = H3(η i PK j );

[0117] where h 3,i represents the third hash value, η i represents a random number selected from , and PK j represents the public key of the second connected vehicle V i .

[0118] The third information value includes:

[0119]

[0120] where c 1,i represents the third information value, h 3,i represents the third hash value, m i represents the message to be sent, and F represents the functional function for adaptively selecting signature or signcryption.

[0121] The information tuple includes:

[0122] σ i = {B i , c 1, i , c 2, i , t i};

[0123] where B i represents the first information value, c 1,i represents the third information value, c 2,i represents the second information value, and t i represents the timestamp when the information tuple is generated.

[0124] S6: After receiving the information tuple, the second connected vehicle compares the timeliness of the timestamp in the information tuple. If the timeliness is satisfied, it restores the connected vehicle message, and uses the information tuple, the public key of the first connected vehicle, and the system parameters to judge the correctness of the restored connected vehicle message. The second connected vehicle receives the connected vehicle message if and only if the restored connected vehicle message is correct.

[0125] After the second connected vehicle receives the information tuple, it verifies the timeliness by comparing the difference between the timestamp in the information tuple and the current system time with a preset threshold: when the difference is less than or equal to the preset threshold, the second connected vehicle uses the signature and signcryption verification algorithm to recover the connected vehicle message, and uses the information tuple, the public key of the first connected vehicle, and the system parameters to judge the correctness of the message. The second connected vehicle receives the connected vehicle message m only when the recovered connected vehicle message is correct. i 。

[0126] The second connected vehicle uses the signature and signcryption verification algorithm to recover the connected vehicle message, including:

[0127] S61: The second connected vehicle calculates the mapping value through elliptic curve scalar multiplication operation according to the private key of the second connected vehicle and the first ciphertext, and calls the fourth hash function H3 to calculate the fourth hash value according to the mapping value.

[0128] The fourth hash value includes:

[0129] h 4,i =H3(sk j B i );

[0130] Among them, h 4,i represents the fourth hash value, sk j represents the private key of the second connected vehicle, and B i represents the first information value.

[0131] S62: The second connected vehicle calls the function F according to the fourth hash value and performs an exclusive OR operation with the third ciphertext to obtain the recovered connected vehicle message.

[0132] The recovered connected vehicle message includes:

[0133]

[0134] Among them, m′ i represents the recovered connected vehicle message, h 4,i represents the fourth hash value, and c 1,i represents the third information value.

[0135] Using the information tuple, the public key of the first connected vehicle, and the system parameters, judging the correctness of the recovered connected vehicle message includes:

[0136] S621: When the second connected vehicle only receives a set of information tuples; the second connected vehicle constructs a single-message discriminant through elliptic curve scalar multiplication based on system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the original connected vehicle message is correct according to whether the single-message discriminant holds. If the single-message discriminant holds, it is determined that the recovered connected vehicle message is correct; if the single-message discriminant does not hold, the recovered connected vehicle message is incorrect, and an error message is returned.

[0137] The single-message discriminant includes:

[0138] c 2,i P = B i + H2((B i + AID i ), m′ i ) PK i ;

[0139] Where c 2,i represents the second information value, P represents the generator of the elliptic curve, B i represents the first information value, AID i represents the pseudo-identity of the first connected vehicle, PK i represents the public key of the first connected vehicle.

[0140] S622: When the second connected vehicle receives multiple sets of information tuples at the same time; the second connected vehicle constructs a batch discriminant through elliptic curve scalar multiplication based on system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the original connected vehicle message is correct according to whether the batch discriminant holds. If the batch discriminant holds, the recovered connected vehicle message is correct; if the batch discriminant does not hold, the recovered connected vehicle message is incorrect, and an error message is returned.

[0141] The batch discriminant includes:

[0142]

[0143] Where c 2,i represents the second information value, P represents the generator of the elliptic curve, B i represents the first information value, AID i represents the pseudo-identity of the first connected vehicle, m′ i represents the recovered original connected vehicle message, PK i represents the public key of the first connected vehicle.

[0144] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A certificateless conditional privacy protection method for vehicle ad hoc networks with adaptive signature and signcryption, characterized in that, Including: The KGC initializes the vehicle networking system parameters based on the system security parameters; The KGC generates a pseudo-identity and a partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, and sends the generated pseudo-identity and partial private key to the corresponding connected vehicle; The connected vehicle generates a private key and a public key of the connected vehicle based on the pseudo-identity, partial private key and system parameters, and uploads the public key to the KGC. The KGC updates the connected vehicle pseudo-identity - public key mapping list and distributes it to all connected vehicles in this area; The first connected vehicle obtains the connected vehicle message to be sent, determines that the connected vehicle of the message recipient is the second connected vehicle, and retrieves the corresponding public key from the connected vehicle pseudo-identity - public key mapping list according to the pseudo-identity of the second connected vehicle; The first connected vehicle executes an adaptive signature cipher algorithm based on its own private key, the connected vehicle message to be sent, the public key of the second connected vehicle and the system parameters according to the privacy requirements of the connected vehicle message to generate an information tuple, and sends the information tuple to the second connected vehicle; After receiving the information tuple, the second connected vehicle compares the timeliness of the timestamps in the information tuple. If the timeliness is satisfied, it recovers the connected vehicle message, and uses the information tuple, the public key of the first connected vehicle and the system parameters to judge the correctness of the recovered connected vehicle message. The second connected vehicle receives the connected vehicle message if and only if the recovered connected vehicle message is correct.

2. An identity-based conditional privacy protection method for vehicle ad hoc networks with adaptive signature and signcryption according to claim 1, characterized in that The KGC initializes the vehicle networking system parameters based on the system security parameters, including: The KGC selects an elliptic curve E that satisfies the security parameter k, and generates partial parameters {P, q, G} of the system, where G is an additive cyclic group defined by the elliptic curve E, and P is a generator of the group G of order prime number q; KGC randomly selects the master key s from the multiplicative group of integers modulo q where and gcd(x, q) = 1}; and calculates the system master public key through elliptic curve scalar multiplication based on the system master key s and partial parameter P KGC configures the first hash function H0, the second hash function H1, the third hash function H2, the fourth hash function H3, and a functional function F for adaptively selecting signatures and signcryption: a × {0, 1} → {0, a}; where, The KGC generates a system parameter set sp = {G, P, q, P pub , F, H0, H1, H2, H3} based on the first hash function H0, the second hash function H1, the third hash function H2, the fourth hash function H3, partial parameters {P, q, G}, and the functional function F through the system parameter generation algorithm.

3. An identity-based conditional privacy protection method for vehicle networking with adaptive signature and signcryption according to claim 2, characterized in that, The KGC generates the pseudo-identity and partial private key of the connected vehicle according to the connected vehicle registration identity information submitted by the connected vehicle, including: The connected vehicle selects a random value from the multiplicative group of integers modulo q and calculates partial identity information of the connected vehicle based on the elliptic curve scalar multiplication operation; the connected vehicle sends the true identity and the partial identity information of the connected vehicle to the KGC through a secure channel together; ​ The KGC obtains a pseudonym identifier and a pseudo-identity through a pseudo-identity generation algorithm based on the received real identity of the connected vehicle, partial identity information, system master key, system master public key, fourth hash function, and first hash function; KGC randomly selects a random value from the multiplicative group of integers modulo q and, based on the random value, the system's public master key, the second hash function, and the pseudo-identity, obtains the partial private key of the connected vehicle through a partial private key generation algorithm.

4. A certificateless conditional privacy method for adaptive signature and signcryption according to claim 1, characterized in that, The connected vehicle generates a private key and a public key of the connected vehicle based on the pseudo-identity, partial private key and system parameters, including: The connected vehicle constructs a partial private key discriminant by using elliptic curve scalar multiplication operation according to the pseudo-identity of the connected vehicle, the partial private key of the connected vehicle, and the system parameters. The connected vehicle receives the pseudo-identity and partial private key of the connected vehicle if and only if the partial private key discriminant holds; Once the partial private key discriminant holds, the connected vehicle selects a random number from the multiplicative group of integers modulo q and calculates the private key of the connected vehicle through the private key generation algorithm using the random number and the partial private key; The connected vehicle calculates the public key of the connected vehicle by using elliptic curve scalar multiplication operation according to the private key of the connected vehicle and the system parameters.

5. An identity-based conditional privacy protection method for vehicle ad-hoc networks with adaptive signature and signcryption according to claim 1, characterized in that The first connected vehicle executes an adaptive signature cipher algorithm based on its own private key, the connected vehicle message to be sent, the public key of the second connected vehicle and the system parameters according to the privacy requirements of the connected vehicle message to generate an information tuple, including: The first connected vehicle obtains a random value from the multiplicative group of integers modulo q and generates a first information value by performing an elliptic curve scalar multiplication operation based on the random value and system parameters; The first connected vehicle calculates a second hash value by invoking the third hash function according to the pseudo-identity of the first connected vehicle, the first information value and the connected vehicle message to be sent; The first connected vehicle multiplies the private key of the first connected vehicle and the second hash value modulo, and then adds the result modulo to the random value to obtain a second information value; The first connected vehicle calculates a third hash value by invoking a fourth hash function based on the random value and the public key of the second connected vehicle, and then performs an exclusive OR operation on the result of invoking a function based on the third hash value and the message to be sent to obtain a third information value; an information tuple is generated based on the first information value, the second information value, the third information value, and the current timestamp.

6. The certificateless conditional privacy protection method for vehicle networking with adaptive signature and signcryption according to claim 1, characterized in that, After receiving the information tuple, if the timeliness is satisfied, the second connected vehicle uses a signature and ciphertext verification algorithm to recover the connected vehicle message, including: After receiving the information tuple, the second connected vehicle compares the difference between the timestamp in the information tuple and the current system time with a preset threshold to verify the timeliness: when the difference is less than or equal to the preset threshold, the second connected vehicle uses a signature and ciphertext verification algorithm to recover the connected vehicle message.

7. An identity-based conditional privacy protection method for vehicle ad-hoc networks with adaptive signature and signcryption according to claim 6, characterized in that Using a signature and ciphertext verification algorithm to recover the connected vehicle message, including: The second connected vehicle calculates a mapping value through elliptic curve scalar multiplication on the private key of the second connected vehicle and the first ciphertext, and calculates a fourth hash value by invoking a fourth hash function based on the mapping value; The second connected vehicle performs an exclusive OR operation on the result of invoking a function F based on the fourth hash value and the third ciphertext to obtain the recovered connected vehicle message.

8. An identity-based conditional privacy protection method for vehicle networking with adaptive signature and signcryption according to claim 7, characterized in that Using the information tuple, the public key of the first connected vehicle, and the system parameters to determine the correctness of the recovered connected vehicle message. Only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message, including: When the second connected vehicle only receives one group of information tuples; the second connected vehicle constructs a single-message discriminant through elliptic curve scalar multiplication on the system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the recovered connected vehicle message is correct based on whether the single-message discriminant holds; only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

9. The certificateless conditional privacy protection method for vehicle ad-hoc networks with adaptive signature and signcryption according to claim 7, characterized in that, Using the information tuple, the public key of the first connected vehicle, and the system parameters to determine the correctness of the recovered connected vehicle message. Only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message, including: When the second connected vehicle receives multiple groups of information tuples at the same time; the second connected vehicle constructs a batch discriminant through elliptic curve scalar multiplication on the system parameters, the first information value, the second information value, the public key of the first connected vehicle, and the pseudo-identity of the first connected vehicle; and determines whether the recovered connected vehicle message is correct based on whether the batch discriminant holds; only when the recovered connected vehicle message is correct, the second connected vehicle receives the connected vehicle message.

Citation Information

Patent Citations

  • Certificate-free generalized proxy signcryption method

    CN104821880A

  • Identity-based generalized multi-recipient anonymous signcryption method

    CN107294972A

  • Certificateless signcryption method for vehicular ad hoc network

    CN115567916A

  • Certificateless aggregation signcryption method based on Internet of Vehicles environment

    CN117749365A

  • Method and device for certificateless partially blind signature

    WO2018119670A1