Vehicle and roadside unit mutual trust authentication and key negotiation method and device
By adopting two-way identity authentication and session key negotiation methods with non-cloneable functions, lightweight hashing and elliptic curve public key cryptography algorithms in the Internet of Vehicles, the problem of low authentication efficiency between vehicle and roadside units is solved, efficient and privacy-protected communication authentication is achieved, and the dependence on trusted centers is reduced.
Patent Information
- Application Number
- CN202510499683.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-21
AI Technical Summary
In the Internet of Vehicles, the identity authentication between the vehicle and the roadside unit is inefficient, especially in high-speed mobile and high-density vehicle scenarios, the prior art requires a trusted center to directly participate in the authentication, resulting in communication delay and inefficiency, and prone to single point failure.
The non-clone function (PUF), lightweight hashing operation, bit-by-bit XOR operation and elliptic curve public key cryptography algorithm are used to realize bidirectional identity authentication and session key negotiation between vehicles and roadside units, reduce the number and length of authentication messages interactions, avoid direct participation of trust centers, and track malicious communication entities through incremental pseudo-identity identification revocation list.
It improves the authentication efficiency of vehicles and roadside units, reduces the delay in transmission of authentication messages, reduces the burden on trusted centers, and enhances the privacy protection of communication entities and prevents identity counterfeiting.
Smart Images

Figure CN120378875A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the authentication of communication entity identities and message authentication in the vehicle networking, belonging to the field of vehicle networking information security, and particularly relates to a mutual trust authentication and key negotiation method and device between a vehicle and a roadside unit. Background Art
[0002] In vehicle networking, vehicles exchange data and share information with each other and with the road to update information such as road conditions, traffic congestion, vehicle positions, and lane capacities, so as to improve traffic conditions, enhance traffic efficiency, avoid vehicle collisions and road accidents, and ensure traffic safety. However, the information exchange between vehicles and between vehicles and the road is transmitted through wireless public channels, making it vulnerable to serious security threats such as identity spoofing attacks, information interception, information tampering, false message injection, and privacy and sensitive information leakage. Currently, identity authentication and key negotiation are mostly used to solve this problem. From the perspective of the implemented technical means, it is necessary to rely on a Trust Authority (TA) to directly participate in the authentication, and mutual trust authentication is achieved through the mutual information transfer among vehicles, the TA, and Road Side Units (RSUs). However, this authentication method not only involves a large number of exchanged messages and a longer number of bits to be exchanged, resulting in a longer time to complete mutual trust authentication of identities, which is not conducive to the timely communication requirements in the vehicle networking scenario. More seriously, in the scenario of high-speed moving and highly dense vehicles, the burden on the TA is very heavy and it is prone to "single point of failure", seriously reducing the communication efficiency and being not conducive to the vehicle networking environment with high-speed vehicle movement and rapid topological structure changes. Moreover, separating the identity authentication and message authentication for processing, how to use lightweight operations to combine the identity authentication and message authentication of vehicle networking communication entities, enable the TA not to directly participate in the authentication, but only be used for the registration of vehicles and RSUs, and the tracking of the identities of malicious communication entities, reduce the quantity and length of message transmission, and improve the authentication efficiency will be the original intention of the design of this authentication method. Summary of the Invention
[0003] The purpose of this application is to provide a mutual trust authentication and session key negotiation method between a vehicle and a roadside unit to solve the problem of low authentication efficiency between the vehicle and the roadside unit.
[0004] In a first aspect, this application provides a mutual trust authentication and session key negotiation method between a vehicle and a roadside unit, including:
[0005] Pre-set the key K of the Trust Authority TA TA , and embed a non-clonable device into the communication entity; the communication entity includes a vehicle Vehicle i and a roadside unit RSU j ;
[0006] After the communication entity receives the registration response, store the triple in the memory of the communication entity; the triple includes the challenge of the communication entity, the pseudo identity identifier of the communication entity, and the security parameters of the communication entity;
[0007] Based on the identity identifier, password, and timestamp of the communication entity, construct an authentication message through the elliptic curve public key cryptography algorithm, and through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message, realize the mutual identity authentication and session key negotiation of the communication entity;
[0008] After the mutual identity authentication and session key negotiation are completed, receive the communication entity to verify the integrity of the received key message;
[0009] Based on the pseudo identity identifier of the sending communication entity, according to the symmetric encryption algorithm and the quadruple stored in the trusted center TA, the trusted center TA completes the tracking of the true identity identifier of the false message sender;
[0010] The communication entity adds the pseudo identity identifier of the false message sender to the incremental pseudo identity identifier revocation list of the communication entity to complete the revocation of the false message sender.
[0011] According to a method for mutual identity authentication and key negotiation between a vehicle and a roadside unit provided by this application, this application has the following technical effects:
[0012] This application provides a method, device, and equipment for mutual identity authentication and key negotiation between a vehicle and a roadside unit. By presetting the trusted center TA key K TA, and embed the unclonable device into the communication entity; when the communication entity receives the registration response, store the triple in the memory of the communication entity; based on the identity identifier, password, and timestamp of the communication entity, construct an authentication message through the elliptic curve public key cryptography algorithm, and achieve mutual trust authentication and session key negotiation through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message; after the identity mutual trust authentication and session key negotiation are completed, the receiving communication entity can verify the integrity of the received critical message; based on the pseudo-identity identifier of the sending communication entity, according to the symmetric encryption algorithm and the quadruple stored in the trusted center TA, the identity of the false message sender can be traced; the communication entity adds the pseudo-identity identifier of the false message sender to its incremental pseudo-identity revocation list to complete the revocation of the false message sender. The mutual trust authentication and key negotiation method between the vehicle and the roadside unit adopts lightweight hashing, exclusive OR, symmetric encryption / decryption, and elliptic curve public key cryptography algorithms to avoid the time cost and computational overhead in the process of certificate generation, distribution, and revocation, reduce the problem of the number and length of authentication message transmission, improve the authentication efficiency of the vehicle and the roadside unit, and adopt pseudo-identity transmission to enhance the privacy protection function of the communication entity. Brief Description of the Drawings
[0013] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0014] Figure 1 It is a schematic flowchart of a method for mutual trust authentication and key negotiation between a vehicle and a roadside unit according to an embodiment of the present application.
[0015] Figure 2 It is a schematic diagram of vehicle Vehicle i registration provided by an embodiment of the present application.
[0016] Figure 3 It is a schematic diagram of roadside unit RSU j registration provided by an embodiment of the present application.
[0017] Figure 4 It is a vehicle Vehicle i and roadside unit RSU j mutual trust authentication and session key negotiation schematic diagram provided by an embodiment of the present application. Detailed Embodiments
[0018] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0019] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0020] This application uses a Physical Unclonable Function (PUF), a lightweight one-way hash operation, a bit-by-bit exclusive OR (XOR), and an elliptic curve public key cryptography algorithm to achieve two-way authentication (or mutual trust authentication) of the identity of vehicles and road side units (RSU) in the Internet of Vehicles environment. The advantages of the prior art are mainly reflected in the following aspects: 1) It realizes two-way identity authentication between the vehicle and the road side unit RSU, which can ensure the legitimacy of the identities of both parties in the information exchange and prevent attackers from impersonating communication entities to send false messages. 2) It realizes the negotiation of session keys between the vehicle and the RSU. The transmission of sensitive messages such as vehicle identity and vehicle location is encrypted and transmitted using session keys, and the receiver uses session keys for decryption to ensure the confidentiality of the transmitted messages. 3) It realizes the anonymity of the communication entity. In the process of authentication message transmission, both the sender and the receiver use anonymous information to exchange information, which protects the privacy of the user and prevents the tracking of communication entities in the Internet of Vehicles. 4) To prevent cloning and physical attacks, this method uses the unclonable function PUF, which has the advantages of light weight, low energy consumption, high throughput, non-copyability, and difficulty for the adversary to counterfeit and predict, and does not require additional storage space to store keys or random numbers. 5) Suitable for identity authentication and session key negotiation of resource-constrained devices, this method uses lightweight hash operations, XOR operations, elliptic curve public key cryptography algorithms, and PUF functions, and the computational overhead is relatively low. 6) This application completes identity authentication and session key negotiation together, which not only reduces the number of authentication message interactions, but also shortens the length of the interaction messages, which can reduce the transmission delay of the authentication messages. 7) The mutual trust authentication of the identities of the communicating parties does not require the direct participation of a trusted third party (TrustAuthority, TA), which not only greatly reduces the burden of identity authentication between intensive communication entities on the TA, but also reduces the possibility of a single point failure of the TA. 8) Track and revoke the identity of malicious communication entities. If it is detected that the received message is false or malicious, the pseudo-identity of the message sender can be sent to TA in an encrypted manner. Then TA can track and revoke the real identity of the sender of the false or malicious message in the access system to prevent communication entities with legitimate identities from doing evil.
[0021] like Figure 1 As shown, an embodiment of the present application provides a method for mutual trust authentication and key negotiation between a vehicle and a roadside unit, which specifically includes the following steps.
[0022] S1: Preset the trusted center TA key K TA and embedding the non-clonable device into a communication entity; the communication entity includes a vehicle i and Roadside Unit RSU j .
[0023] S2: After the communication entity receives the registration response, store the triple in the memory of the communication entity; the triple includes the challenge of the communication entity, the pseudo identity identifier of the communication entity, and the security parameters of the communication entity.
[0024] S3: Based on the identity identifier, password, and timestamp of the communication entity, construct an authentication message through the elliptic curve public key cryptography algorithm, and through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message, realize the mutual trust authentication of the identity of the communication entity and the session key negotiation.
[0025] S4: After the mutual trust authentication and session key negotiation are completed, receive the communication entity to verify the integrity of the received key message.
[0026] S5: Based on the pseudo identity identifier of the sender communication entity, according to the symmetric encryption algorithm and the quadruple stored in the trusted center TA, the trusted center TA completes the tracking of the true identity identifier of the false message sender.
[0027] S6: The communication entity adds the pseudo identity identifier of the false message sender to the incremental pseudo identity identifier revocation list of the communication entity to complete the revocation of the false message sender.
[0028] A method for mutual trust authentication and key negotiation between a vehicle and a roadside unit is divided into four stages: namely, system initialization, vehicle registration, roadside unit RSU registration, and mutual trust authentication and session key negotiation stage between the vehicle and the RSU.
[0029] System initialization stage: The system administrator completes the presetting of the TA key K TA and the embedding of the physically unclonable function PUF i in the vehicle Vehicle i and the embedding of the physically unclonable function PUF j in the roadside unit RSU j .
[0030] The system administrator selects the elliptic curve equation y 2 =x 3 +ax + b (mod p), where a and b are elliptic curve parameters, p is a large prime number, and it is required that the discriminant 4a 3 +27b 2 ≠0 (mod p) to ensure that the elliptic curve has no singular points.
[0031] Furthermore, in an exemplary embodiment, S2 can be replaced by the following steps.
[0032] S201: The communication entity selects its own identity identifier and password, and generates a binary string.
[0033] S202: Use the binary string as a challenge, determine a response according to the non-clonable device embedded in the communication entity, and use the response as the private key of the communication entity.
[0034] Vehicle i Select its own identity identifier ID i and the key PW i , generate a binary string C i as a challenge, and through the non-clonable function PUF embedded in Vehicle i obtain a response R i = PUF i (C i ) as the private key of Vehicle i . i
[0035] S203: Based on the identity identifier, the password, and the private key, calculate a registration request message, and send the registration request message to the trusted center TA.
[0036] The Vehicle i calculates R i = PUF i (C i ) and PID i = h(ID i || PW i || R i ), uses PID i as its pseudo-identity identifier, and sends the registration request message ReqV: <ID i , PID i , C i , R i > to TA through a secure channel.
[0037] S204: When the trusted center TA receives the registration request message ReqV, it determines whether the identity identifier ID i exists.
[0038] If so, the communication entity Vehicle i re-selects an identity identifier.
[0039] If not, the trusted center TA calculates the obfuscated identity identifier of the registered communication entity Vehicle i and stores the quadruple in the database of the trusted center TA; the quadruple includes the communication entity Vehiclei The identity identifier of, the communication entity Vehicle i The pseudo-identity identifier of, the communication entity Vehicle i The challenge of and the response of the communication entity.
[0040] S205: The trusted center TA sends a registration response to the registered communication entity Vehicle i through a secure channel, and the registration response is the obfuscated identity identifier of the registered communication entity calculated by the trusted center TA.
[0041] S206: When the registered communication entity Vehicle i receives the registration response, it determines the key and triple of the trusted center TA and stores the triple in the memory of the registered communication entity Vehicle i ; The triple includes the challenge of the registered communication entity Vehicle i the pseudo-identity identifier of the registered communication entity Vehicle i and the security parameter of the registered communication entity Vehicle i .
[0042] As Figure 2 shown, Vehicle i after receiving the registration response ResV: <MID i >, calculates Then stores the triple (C i , PID i , SK TA ) in its memory.
[0043] As Figure 3 shown, the roadside unit RSU j selects its own identity identifier ID j and PW j , generates a binary string C j as the challenge, and obtains the response output R j = PUF j (C j ) through the physically unclonable function PUF j embedded in the RSU j and uses R j as its private key. Then, the RSU j calculates PID j = h(ID j || PW j || R j ) and sends a registration request ReqR to the TA through a secure channel; ReqR is <IDj , PID j , C j , R j >.
[0044] After TA receives the registration request ReqR, it first checks the ID j for existence. If the ID j has been used, it notifies the RSU j to reselect an identity; otherwise, TA calculates and stores the 4-tuple (ID j , PID j , C j , R j ) in its database, and then sends a registration response ResR: <MID j > to the RSU through a secure channel j .
[0045] RSU j receives the registration response ResR: <MID j >, calculates and then stores the triple (C j , PID j , RK TA ) in its memory.
[0046] Furthermore, in an exemplary embodiment, S3 can be replaced by the following steps.
[0047] S301: Input the identity ID i of the vehicle Vehicle i , password PW i and timestamp t1, and obtain the message Msg1 according to the elliptic curve public key cryptography algorithm.
[0048] S302: When the roadside unit RSU j receives the message Msg1, it determines the validity of the timestamp t1 and completes the authentication of the vehicle Vehicle i based on the verification parameter A i in the message Msg1, and determines the session key where the verification parameter A i is h(PID i ||PID j ||K TA ||t1); where h() is a one-way hash function; PID i is the pseudo-identity of the vehicle Vehicle i ; PID j is the pseudo-identity of the roadside unit RSU jThe pseudo-identity identifier of; K TA is TA's secret key; t1 is the timestamp when the message Msg1 is sent.
[0049] S303: The roadside unit RSU j generates a timestamp t2, extracts the triple stored in the first memory, completes the verification of the parameter A1 to be verified and the session key calculation, and constructs an authentication message Msg2 according to the elliptic curve public key cryptography algorithm; the first memory is the memory of the roadside unit RSU j memory.
[0050] S304: When the vehicle Vehicle i receives the message Msg2, determines the validity of the timestamp t2, and according to the parameter B to be verified in the message Msg2 j completes the authentication of the roadside unit RSU j and determines the session key of the vehicle Vehicle i session key The parameter B to be verified j is h(PID j ||PID i ||K TA ||t2); where t2 is the timestamp when the message Msg2 is sent.
[0051] Among them, S301 specifically includes:
[0052] S3011: The vehicle Vehicle i inputs its identity identifier ID i and password PW i , and extracts the triple of the vehicle Vehicle i from the second memory; the triple is (C i ,PID i ,SK TA ); where C i is the challenge of the vehicle Vehicle i ; PID i is the pseudo-identity identifier of the vehicle Vehicle i ; SK TA is the security parameter of the vehicle Vehicle i ; the second memory is the memory of the vehicle Vehicle i memory.
[0053] S3012: Based on the triple, using the embedded physically unclonable function PUF i (), determine the vehicle Vehiclei The response R i = PUF i (C i ), and determine the pseudo identity identifier of the vehicle Vehicle according to i where R i is the response of the vehicle Vehicle i .
[0054] S3013: Judge whether it holds.
[0055] If not, confirm that the user identity authentication of the vehicle Vehicle fails, prohibit the vehicle Vehicle i from logging in, and terminate the current identity mutual trust authentication and session key negotiation. i
[0056] If so, the vehicle Vehicle i generates the current timestamp t1, and determines the key K of the trusted center TA according to TA .
[0057] S3014: Based on the key K TA , according to A i = h(PID i || PID j || K TA || t1), determine the parameter A to be verified of the vehicle Vehicle i ; where h() is a hash operation; A i is the parameter to be verified of the vehicle Vehicle i i .
[0058] S3015: Based on the response R of the vehicle Vehicle i determine the public key Pub of the vehicle Vehicle according to the elliptic curve public key cryptography algorithm i i i .
[0059] S3016: Based on the public key Pub i , the vehicle Vehicle i sends a message Msg1 to the roadside unit RSU j ; the Msg1 is <PID i , A i , Pub i , t1>.
[0060] As shown Figure 4 in the figure, the user inputs the identity identifier ID i of Vehicle i and the password PW i , and extracts C i , PID i and SK TA from its memory, and then calculates R i =PUF i (C i ) and subsequently checks If the two are not equal, it indicates that the user identity authentication fails, and the system terminates the current identity mutual trust authentication and session key negotiation process; otherwise, Vehicle i generates the current timestamp t1, calculates A i =h(PID i ||PID j ||K TA ||t1), and calculates its public key Pub i =R i ·G based on the elliptic curve public key cryptography algorithm, and then sends the message Msg1: <PID j , A i , Pub i , t1> to the RSU i .
[0061] Among them, S302 specifically includes:
[0062] S3021: When the roadside unit RSU j receives the message Msg1, it checks the validity of the timestamp t1.
[0063] S3022: If the absolute value of the difference between the timestamp t1 and the current time exceeds the preset value, it is confirmed that the timestamp t1 is invalid, and the current identity mutual trust authentication and session key negotiation process is terminated.
[0064] S3023: If the absolute value of the difference between the timestamp t1 and the current system time does not exceed the preset value, it is confirmed that the timestamp t1 is valid.
[0065] S3024: The roadside unit RSU j extracts the challenge C j of the roadside unit RSU j , the pseudo identity identifier PID j and the security parameter RK TA from the first memory.
[0066] S3025: According to the embedded unclonable function PUFj (), determine the roadside unit RSU j Response R j = PUF j (C j ); where C j is the challenge of the roadside unit RSU j .
[0067] S3026: According to determine the key K of the trusted center TA TA , and according to calculate the parameter to be verified
[0068] S3027: Detect whether it holds.
[0069] If not, confirm that the authentication of the vehicle Vehicle i fails, and terminate the current mutual identity authentication and session key negotiation process.
[0070] If so, the roadside unit RSU j confirms the legitimacy of the identity of the vehicle Vehicle i , and according to determine the session key where is the session key calculated by the roadside unit RSU j ; R j is the response of the roadside unit RSU j ; Pub i is the public key of the vehicle Vehicle i ; R i is the response of the vehicle Vehicle i , and G is a publicly known base point on the elliptic curve.
[0071] RSU j After receiving the message Msg1, first check the validity of t1. If the absolute value of the time difference between t1 and the current system time exceeds the preset value, terminate the current mutual identity authentication and session key negotiation process; otherwise, consider t1 valid, and RSU j extracts C j , PID j and RK TA from its memory, and calculates R j = PUF j (C j ), and Then check If they are not equal, it indicates that Vehiclei The identity authentication fails, and the system terminates the current identity mutual trust authentication and session key negotiation process; otherwise, the Vehicle i 's identity is verified, and then the RSU j calculates the session key
[0072] Among them, S303 specifically includes:
[0073] S3031: The roadside unit RSU j generates a timestamp t2.
[0074] S3032: According to B j = h(PID j ||PID i ||K TA ||t2) to determine the parameter B to be verified of the roadside unit RSU j , where PID j is the pseudo-identity identifier of the roadside unit RSU j ; PID j is the pseudo-identity identifier of the vehicle Vehicle i ; K i is the key of the trusted center TA; t2 is the timestamp; B TA is the parameter to be verified of the roadside unit RSU j . j
[0075] S3033: According to Pub j = R j ·G to determine the public key Pub j of the roadside unit RSU j ; where G is a publicly known base point on the elliptic curve.
[0076] S3034: Based on the pseudo-identity identifier PID j of the roadside unit RSU j , the parameter B to be verified of the roadside unit RSU j , the response R j of the roadside unit RSU j , and the timestamp t2, and Pub j = R j ·G to construct the message Msg2, and send the message Msg2 to the vehicle Vehicle j ; the Msg2 is <PID i , B j , Pub j , t2>. j
[0077] Among them, S304 specifically includes:
[0078] S3041: When the vehicle Vehicle i receives the message Msg2, determine the validity of the timestamp t2.
[0079] S3042: If the absolute value of the difference between the timestamp t2 and the current system time exceeds a preset value, confirm that the timestamp t2 is invalid, and terminate the current identity mutual trust authentication and session key negotiation.
[0080] S3043: If the absolute value of the difference between the timestamp t2 and the current system time does not exceed the preset value, confirm that the timestamp t2 is valid.
[0081] S3044: According to determine the parameters to be verified of the roadside unit RSU j
[0082] S3045: Judge whether it holds.
[0083] If not, confirm that the authentication of the roadside unit RSU j fails, and terminate the current identity mutual trust authentication and session key negotiation process.
[0084] If so, confirm the legitimacy of the identity of the roadside unit RSU j and determine the verification result.
[0085] S3046: Based on the verification result, according to calculate the session key of the vehicle Vehicle i
[0086] Furthermore, in an exemplary embodiment, S4 can be replaced by the following steps.
[0087] S401: The vehicle Vehicle i , according to e = h(M v ) to determine the hash value e of the key message; where M v is the key message.
[0088] S402: Based on the hash value of the key message, let the vehicle Vehicle i select a random integer k v ; the random integer k v satisfies 1 ≤ k v < n, where n is the order of the elliptic curve subgroup.
[0089] S403: According to the elliptic curve public key cryptography algorithm, use \((x1, y1)=k\) v ·G to determine the temporary point of the vehicle Vehicle i ; where, x1 is the abscissa of the temporary point; y1 is the ordinate of the temporary point.
[0090] S404: The vehicle Vehicle i takes the abscissa x1 of the temporary point and uses \(r = x1\ mod\ n\) to determine the parameter r; where, r is the first signature parameter and constitutes the first part of the signature; mod is the modulo operation.
[0091] If r is equal to 0, reselect the random integer k v .
[0092] If r is not equal to 0, use to determine the second signature parameter s; where, s is the second signature parameter and constitutes the second part of the signature; is the multiplicative inverse of the random integer k v under modulo n.
[0093] S405: If s is equal to 0, reselect the random integer k v ; determine the first signature parameter r.
[0094] S406: Based on the first signature parameter r and the second signature parameter s, determine the signature SIGN v as \((r, s)\).
[0095] S407: Based on the key message M v , the signature SIGN v and the public key Pub i , the vehicle Vehicle i constructs a new message Msg; Msg is <M v , SIGN v , Pub i >, and sends the new message Msg: <M v , SIGN v , Pub i > to the roadside unit RSU j .
[0096] S408: When the roadside unit RSU j receives the new message Msg, the roadside unit RSU j checks the validity of the signature SIGN v .
[0097] S409: If any one of 1 ≤ r < n or 1 ≤ s < n is not satisfied, confirm that the signature (r, s) is invalid, and discard the received new message Msg.
[0098] If 1 ≤ r < n and 1 ≤ s < n are satisfied, confirm that the signature (r, s) is valid, and the roadside unit RSU j extracts the key message M from the new message Msg v .
[0099] S410: Based on the key message M v , use w = s -1 mod n to determine w; where w is the multiplicative inverse of the signature parameter s modulo n; s -1 is the multiplicative inverse of s modulo n.
[0100] S411: Based on the hash value e = h(M v ) of the key message M and the multiplicative inverse w of the signature parameter s modulo n, according to u1 = e · w mod n and u2 = r · w mod n, determine the intermediate values u1 and u2 of the roadside unit RSU v . j
[0101] S412: Based on the intermediate values u1 and u2, according to (x2, y2) = u1 · G + u2 · Pub i , determine the coordinates of the temporary point; where x2 is the abscissa of the temporary point; y2 is the ordinate of the temporary point; u1 is the intermediate value 1; u2 is the intermediate value 2; Pub i is the public key of the vehicle Vehicle i .
[0102] S413: Based on the abscissa x2 of the temporary point, determine the verification parameter v according to v = x2 mod n; where x2 is the abscissa of the temporary point.
[0103] S414: Extract r from the signature, determine whether v = r holds, and determine the detection result.
[0104] If so, confirm that the detection result is that the key message M v has not been tampered with during transmission, and the roadside unit accepts the key message M v .
[0105] If not, confirm that the detection result is that the key message M v has been tampered with during transmission, and discard the key message M v .
[0106] The vehicle Vehicle i The specific steps for sending key message integrity detection are as follows:
[0107] Step1.1: Vehicle i Calculate the hash value e of the key message M to be sent, where e = h(M v ). v )
[0108] Step1.2: Vehicle i Select a random integer k v , such that 1 ≤ k v < n.
[0109] Step1.3: Vehicle i Calculate a temporary point (x1, y1) = k v ·G.
[0110] Step1.4: Calculate and generate a signature. Vehicle i First, take the coordinate value of x1 and calculate r = x1 mod n. If r = 0, then reselect k v , and return to step1.3; otherwise, Vehicle i Calculate where is the multiplicative inverse of k v modulo n. If s = 0, then reselect k v , and return to step1.3.
[0111] Step1.5: Vehicle i Generate a signature SIGN v = (r, s) according to the calculated r and s, and use the key message M v , the signature SIGN v = (r, s) and its public key Pub i to construct a new message Msg: <M v , SIGN v , Pub i >, and then send Msg to the RSU j .
[0112] Step1.6: RSU j After receiving the message Msg, first check the validity of the signature. If 1 ≤ r < n and 1 ≤ s < n, then the signature is valid and proceed to Step1.7; otherwise, the signature is invalid and the received message Msg is discarded.
[0113] Step1.7: RSU j Extract the key message M v from Msg, and calculate e = h(Mv ),w = s -1 mod n, where s -1 is the multiplicative inverse of s modulo n.
[0114] Step1.8: RSU j Calculate the intermediate values u1 and u2, where u1 = e·w mod n, u2 = r·w mod n, and then calculate the temporary point (x2, y2) = u1·G + u2·Pub i .
[0115] Step1.9: RSU j Take the coordinate value of x2, calculate v = x2 mod n, and then extract r from the received signature SIGN v = (r, s), and then check if v = r holds. If the two are equal, it indicates that the critical message M v has not been tampered with during transmission, and accept the critical message M v ; if the two are not equal, it indicates that the said critical message M v has been tampered with during transmission, then discard the received critical message M v .
[0116] The roadside unit RSU j sends the integrity detection of the critical message M R specifically includes the following steps:
[0117] Step2.1: RSU j Calculate the hash value e of the critical message M R to be sent, where e = h(M R );
[0118] Step2.2: RSU j Select a random integer k R , such that 1 ≤ k R < n.
[0119] Step2.3: RSU j Calculate a temporary point (x1, y1) = k R ·G.
[0120] Step2.4: RSU j Take the coordinate value of x1, calculate r = x1 mod n. If r = 0, reselect k R , and return to step2.3; otherwise, RSU j calculate where is the multiplicative inverse of k R modulo n. If s = 0, reselect kR , return to Step2.3.
[0121] Step2.5: RSU j Generate a signature SIGN according to the calculated r and s R =(r, s), and use the key message M R , the signature SIGN R =(r, s) and its public key Pub j Construct a new message Msg: <M R , SIGN R , Pub j >, and then send Msg to Vehicle i .
[0122] Step2.6: Vehicle i After receiving the message Msg, first check the validity of the signature. If 1 ≤ r < n and 1 ≤ s < n, the signature is valid and proceed to Step2.7; otherwise, the signature is invalid and the received new message Msg is discarded.
[0123] Step2.7: Vehicle i Extract the key message M from Msg R , and calculate e = h(M R ), w = s -1 mod n, where s -1 is the multiplicative inverse of s modulo n.
[0124] Step2.8: Vehicle i Calculate the intermediate values u1 and u2, where u1 = e·w mod n, u2 = r·w mod n, and then calculate the temporary point (x2, y2) = u1·G + u2·Pub j .
[0125] Step2.9: Vehicle i Take the coordinate value of x2, calculate v = x2 mod n, and then extract r from the received signature SIGN R =(r, s), and then check if v = r holds. If the two are equal, it indicates that the key message M R has not been tampered with during transmission, and accept the key message M R ; if the two are not equal, it indicates that the key message M R has been tampered with during transmission, and then discard the received key message M R .
[0126] Furthermore, in an exemplary embodiment, S5 can be replaced by the following steps.
[0127] S501: If the sender uses a pseudo identity identifier PID m to complete malicious behavior, the receiver obtains the key K of the trusted center TA TA ; The receiver includes the roadside unit RSU j and the vehicle Vehicle i .
[0128] S502: If the receiver is the roadside unit RSU j , then the roadside unit RSU j extracts parameters from the first memory; The parameters include the challenge C j of the roadside unit RSU j and the security parameter RK TA .
[0129] S503: The roadside unit RSU j determines the key K of the trusted center TA according to R j = PUF j (C j ) and ; where C TA is the challenge of the RSU j ; R j is the response of the RSU j ; PUF j () is the non-clonable function embedded in the RSU j . j
[0130] S504: The roadside unit RSU j determines the encrypted pseudo identity identifier of the false message sender according to , and sends the encrypted pseudo identity identifier to the trusted center TA; where CPID m is the encrypted pseudo identity identifier; is the encryption operation on PID TA using the key K of the trusted center m ; PID m is the pseudo identity identifier of the false message sender.
[0131] S505: After receiving the encrypted pseudo identity identifier CPID m , the trusted center TA performs a decryption operation to restore the pseudo identity identifier PID m of the false message sender, where represents that the trusted center decrypts CPID TA using its key K m .
[0132] S506: Look up in the said quadruple respectively based on the pseudo identity identifier PID m to determine the real identity ID of the malicious node m .
[0133] S507: If the real identity ID of the said malicious actor m is found in the quadruple of the said vehicle Vehicle i , confirm that the real identity of the said malicious actor comes from the vehicle Vehicle m .
[0134] S508: If the real identity of the said malicious actor is found in the quadruple of the said roadside unit RSU j , confirm that the real identity of the said malicious actor comes from the roadside unit RSU m , and complete the tracking of the malicious node
[0135] Furthermore, in an exemplary embodiment, S6 can be replaced by the following steps
[0136] S601: After the communication entity receives a false or malicious message, generate a warning message M w ; the warning message M w includes the pseudo identity identifier PID of the malicious communication entity A .
[0137] S602: The communication entity calculates the key K of the trusted center TA TA ; when the communication entity is the roadside unit RSU j , the RSU j extracts the triple (C j , PID j , RK TA ) from the first memory; by calculating R j = PUF j (C j ), determine the key K of TA TA ; when the communication entity is the vehicle Vehicle i , the vehicle Vehicle i extracts the triple (C i , PID i , SKTA) from the second memory, and by calculating R i = PUF i (C i ), determine the key K of TA TA .
[0138] S603: Based on the key K of the Trusted Authority TA TA , the communication entity encrypts the warning message M w to generate the encrypted warning message CM w , and sends the encrypted warning message CM w to the Trusted Authority TA; where the encrypted warning message CM w is
[0139] S604: After receiving the encrypted warning message CM w , the Trusted Authority TA broadcasts the encrypted warning message CM w to the communication entity.
[0140] S605: After receiving the broadcast message CM from the Trusted Authority TA w , the communication entity decrypts the encrypted warning message CM TA according to the key K w to obtain the original warning message M w ; where the original warning message M w is
[0141] S606: The communication entity determines the pseudo-identity identifier PID w of the communication entity that sent the false or malicious message according to the original warning message M A .
[0142] S607: When receiving the message Msg1, the Road Side Unit RSU j checks whether the pseudo-identity identifier PID i of the sender is in the Incremental Pseudo-Identity Revocation List IPRL.
[0143] S608: If it is, the Road Side Unit RSU j confirms that the vehicle Vehicle i is a revoked malicious vehicle, and terminates the identity mutual trust authentication and session key negotiation between the Road Side Unit RSU j and the vehicle Vehicle i .
[0144] S609: When receiving the message Msg2, the vehicle Vehicle i detects whether the PID j is in its Incremental Pseudo-Identity Revocation List IPRL.
[0145] S610: If it is, the vehicle Vehicle iConfirm the roadside unit RSU j As a revoked malicious roadside unit, terminate the vehicle Vehicle i With the roadside unit RSU j Mutual trust authentication and session key negotiation of the identity, and complete the revocation of the malicious node; the malicious node includes the vehicle Vehicle i Or the roadside unit RSU j .
[0146] The tracking and revocation of malicious nodes specifically include:
[0147] Step3.1: After receiving a false or malicious message, the communication entity generates a warning message M w . The communication entity includes the roadside unit RSU j And the vehicle Vehicle i , the warning message M w Contains the pseudo-identity identifier PID of the malicious communication entity A .
[0148] Step3.2: The communication entity calculates the key K of the trusted center TA TA . When the communication entity is the roadside unit RSU j , the RSU j Extracts the triple (C j , PID j , RK TA ) from its memory, and determines the key K of TA by calculating R j = PUF j (C j ); when the communication entity is the vehicle Vehicle Determine the key K of TA TA ; when the communication entity is the vehicle Vehicle i , the vehicle Vehicle i Extracts the triple (C i , PID i , SK TA ) from its memory, and determines the key K of TA by calculating R i = PUF i (C i ). Determine the key K of TA TA .
[0149] Step3.3: The communication entity (which can be either the roadside unit RSU j , or the vehicle Vehicle i ) uses the calculated key K of the trusted center TA TA To the warning message M wEncrypt it to generate an encrypted warning message CM w , and send CM w to the trusted center TA, where
[0150] Step3.4: The trusted center TA receives the encrypted warning message CM w , and broadcasts CM w to the communication entities, where the communication entities include the roadside unit RSU j and the vehicle Vehicle i .
[0151] Step3.5: After receiving the broadcast message CM w from TA, the communication entity uses the calculated key K TA of TA to decrypt the encrypted warning message CM w to obtain the original warning message M w , where
[0152] Step3.6: The communication entity determines the pseudo identity identifier PID w of the communication entity that sends false or malicious messages according to the original warning message M A , and adds it to the incremental pseudo identity identifier revocation list IPRL of the communication entity.
[0153] Step3.7: If receiving the message Msg1: <PID i ,A i ,Pub i ,t1>, the roadside unit RSU j checks whether the pseudo identity identifier PID i of the sender is in the incremental pseudo identity identifier revocation list IPRL of the roadside unit RSU j ; if receiving the message Msg2: <PID j ,B j ,Pub j ,t2>, the vehicle Vehicle i checks whether the pseudo identity identifier PID j of the sender is in the incremental pseudo identity identifier revocation list IPRL of the vehicle Vehicle i .
[0154] Step3.8: If the check result is positive, the message receiver terminates the identity mutual trust authentication and session key negotiation with the message sender, and completes the revocation of the identity of the false or malicious message sender.
[0155] For the convenience of elaborating this application, the identifiers to be used are defined as shown in Table 1:
[0156] Table 1 Identifier Definition
[0157]
[0158]
[0159] In this article, specific examples are used to elaborate on the principles and implementation manners of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. To sum up, the content of this specification should not be construed as a limitation to this application.
Claims
1. A mutual trust authentication and key negotiation method between a vehicle and a roadside unit, characterized in that The method for mutual trust authentication and key negotiation between the vehicle and the roadside unit includes: Pre-set the trusted center TA key K TA , and embed the non-clonable device into the communication entity; the communication entity includes a vehicle Vehicle i and a roadside unit RSU j ; After the communication entity receives the registration response, store the triple in the memory of the communication entity; the triple includes the challenge of the communication entity, the pseudo identity identifier of the communication entity, and the security parameter of the communication entity; Based on the identity identifier, password, and timestamp of the communication entity, construct an authentication message through the elliptic curve public key cryptography algorithm, and achieve mutual trust authentication of the identity of the communication entity and session key negotiation through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message; After the mutual trust authentication of the identity and session key negotiation are completed, receive the verification of the integrity of the critical message received by the communication entity; Based on the pseudo identity identifier of the sending communication entity, according to the symmetric encryption algorithm and the quadruple stored in the trusted center TA, the trusted center TA completes the tracking of the true identity identifier of the false message sender; The communication entity adds the pseudo identity identifier of the false message sender to the incremental pseudo identity identifier revocation list of the communication entity to complete the revocation of the false message sender.
2. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, wherein When the communication entity receives the registration response, storing the triple in the memory of the communication entity specifically includes: The communication entity selects its own identity identifier and password to generate a binary string; Use the binary string as a challenge, determine the response according to the non-clonable device embedded in the communication entity, and use the response as the private key of the communication entity; Based on the identity identifier, the password, and the private key, calculate the registration request message and send the registration request message to the trusted center TA; When the trusted center TA receives the registration request message, determine whether the identity identifier exists; If so, instruct the communication entity to re-select the identity identifier; If not, the trusted center TA calculates the obfuscated identity identifier of the registered communication entity and stores the quadruple in the database of the trusted center TA; the quadruple includes the identity identifier of the communication entity, the pseudo identity identifier of the communication entity, the challenge of the communication entity, and the response of the communication entity; The trusted center TA sends a registration response to the registered communication entity through a secure channel, and the registration response is the obfuscated identity identifier of the registered communication entity calculated by the trusted center TA; When the registered communication entity receives the registration response, determine the key and triple of the trusted center TA, and store the triple in the memory of the registered communication entity; the triple includes the challenge of the registered communication entity, the pseudo identity identifier of the registered communication entity, and the security parameter of the registered communication entity.
3. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that Based on the identity identifier, password, and timestamp of the communication entity, construct an authentication message through the elliptic curve public key cryptography algorithm, and achieve mutual trust authentication of the identity of the communication entity and session key negotiation through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message, specifically including: Input the identity ID of the vehicle i and the identity ID i , password PW i and timestamp t1, and obtain message Msg1 according to the elliptic curve public key cryptography algorithm; When the roadside unit RSU j receives the message Msg1, it determines the validity of the timestamp t1 and, based on the parameter A to be verified in the message Msg1 i completes the authentication of the vehicle Vehicle i and determines the session key The parameter A to be verified i is h(PID i ||PID j ||K TA ||t1); where h() is a one-way hash function; PID i is the pseudo-identity identifier of the vehicle Vehicle i ; PID j is the pseudo-identity identifier of the roadside unit RSU j ; K TA is the key of TA; t1 is the timestamp when the message Msg1 is sent; The roadside unit RSU j generates a timestamp t2, extracts the triple stored in the first memory, completes the verification of the parameter A1 to be verified and the calculation of the session key and constructs an authentication message Msg2 according to the elliptic curve public key cryptography algorithm; the first memory is the memory of the roadside unit RSU j ; When the vehicle i After receiving the message Msg2, the validity of the timestamp t2 is determined, and the verification parameter B in the message Msg2 is j Complete the RSU j The identity authentication of the vehicle is determined i Session key The parameter to be verified B j h(PID j ||PID i ||K TA ||t2); wherein t2 is the timestamp when the message Msg2 is sent.
4. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 3, characterized in that Input the identity ID of the vehicle Vehicle i and the password PW i and the timestamp t1, and obtain the message Msg1 according to the elliptic curve public key cryptography algorithm, specifically including: i The vehicle i inputs its identity ID i and password PW i , and extracts the triple of the vehicle i from the second memory; the triple is (C i , PID i , SK TA ); where C i is the challenge of the vehicle i ; PID i is the pseudo identity ID of the vehicle i ; SK TA is the security parameter of the vehicle i ; the second memory is the memory of the vehicle i ; Based on the triplet, using the embedded unclonable function PUF i (), determine the vehicle Vehicle i The response R i =PUF i (C i ), and according to Determine the vehicle i Pseudo-identity Among them, R i for the vehicle i Response; Judge Whether it holds; If not, confirm the vehicle Vehicle i The user identity authentication fails, and the vehicle Vehicle is prohibited i from logging in, and terminate the current identity mutual trust authentication and session key negotiation; If so, the vehicle i generates a current timestamp t1 and, according to determines the key K of the trusted center TA TA ; Based on the key K TA , according to A i = h(PID i || PID j || K TA || t1), determine the parameter A i to be verified for the vehicle Vehicle i ; where h() is a hashing operation; A i is the parameter i to be verified for the vehicle Vehicle Based on the vehicle Vehicle i response R i , according to the elliptic curve public key cryptography algorithm, determine the public key Pub i of the vehicle Vehicle i ; Based on the public key Pub i , the vehicle Vehicle i sends a message Msg1 to the roadside unit RSU j ; the Msg1 is <PID i , A i , Pub i , t1>.
5. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 3, characterized in that When the roadside unit RSU j receives the message Msg1, it determines the validity of the timestamp t1 and, based on the parameter A to be verified in the message Msg1 i completes the authentication of the vehicle Vehicle i and determines the session key Specifically, it includes: When the roadside unit RSU j receives the message Msg1, it checks the validity of the timestamp t1; If the absolute value of the difference between the timestamp t1 and the current time exceeds a preset value, confirm that the timestamp t1 is invalid, and terminate the current mutual identity authentication and session key negotiation process; If the absolute value of the difference between the timestamp t1 and the current system time does not exceed the preset value, confirm that the timestamp t1 is valid; The roadside unit RSU j Extract the challenge C j , the pseudo identity PID j and the security parameter RK j from the first memory TA ; According to the embedded unclonable function PUF j (), determine the roadside unit RSU j response R j = PUF j (C j ); where C j is the challenge of the roadside unit RSU j ; According to determine the key K of the trusted center TA TA , and according to calculate the parameter to be verified Detection Whether it holds; Otherwise, confirm that the identity authentication of the vehicle Vehicle i fails, and terminate the current identity mutual trust authentication and session key negotiation process; If yes, the roadside unit RSU j Confirm the vehicle i The legitimacy of the identity and Determine the session key in, The road side unit RSU j The calculated session key; R j The road side unit RSU j Response from Pub i for the vehicle i The public key of R i for the vehicle i The response is G, which is a public base point on the elliptic curve.
6. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 3, characterized in that The roadside unit RSU j generates a timestamp t2, extracts the triple stored in the first memory, completes the verification of the parameter A1 to be verified and the calculation of the session key and constructs an authentication message Msg2 according to the elliptic curve public key cryptography algorithm, specifically including: The roadside unit RSU j Generate a timestamp t2; According to B j =h(PID j ||PID i ||K TA || t2) Determine the roadside unit RSU j The parameter B to be verified j , where PID j The road side unit RSU j Pseudo-identity identifier; PID i for the vehicle i Pseudo-identity of K TA is the key of the trusted center TA; t2 is the timestamp; B j The road side unit RSU j Parameters to be verified; According to Pub j = R j ·G to determine the public key Pub j of the roadside unit RSU j ; where G is a publicly known base point on the elliptic curve; Based on the roadside unit RSU j 's pseudo identity identifier PID j , the roadside unit RSU j 's parameter B to be verified j , the roadside unit RSU j 's response R j and the timestamp t2, according to Pub j = R j ·G to construct the message Msg2, and send the message Msg2 to the vehicle Vehicle i ; The Msg2 is <PID j , B j , Pub j , t2>.
7. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 3, characterized in that When the vehicle i receives the message Msg2, it determines the validity of the timestamp t2 and, based on the parameter B to be verified in the message Msg2 j completes the authentication of the roadside unit RSU j and determines the session key of the vehicle i Specifically, it includes: Specifically, it includes: When the vehicle i receives the message Msg2, it determines the validity of the timestamp t2; If the absolute value of the difference between the timestamp t2 and the current system time exceeds the preset value, confirm that the timestamp t2 is invalid, and terminate the current mutual identity authentication and session key negotiation; If the absolute value of the difference between the timestamp t2 and the current system time does not exceed the preset value, confirm that the timestamp t2 is valid; According to determine the parameter to be verified of the roadside unit (RSU) j Judge whether it holds; Otherwise, confirm that the authentication of the roadside unit (RSU) j fails, and terminate the current mutual authentication and session key negotiation process; If so, confirm the legitimacy of the identity of the roadside unit (RSU) j and determine the verification result. Based on the verification result, according to calculate the session key of the vehicle Vehicle i session key 8. The vehicle and roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that After the mutual identity authentication and session key negotiation are completed, the communication entity verifies the integrity of the key messages received: specifically including: The vehicle i , determines the hash value e of the key message according to e = h(M v ); where M v is the key message; Based on the hash value of the key message, let the vehicle Vehicle i select a random integer k v ; the random integer k v satisfies 1 ≤ k v < n, where n is the order of the elliptic curve subgroup; According to the elliptic curve public key cryptography algorithm, using (x1, y1) = k v ·G, determine the temporary point of the vehicle Vehicle i ; where x1 is the abscissa of the temporary point; y1 is the ordinate of the temporary point The vehicle i Take the abscissa x1 of the temporary point, and use r = x1 mod n to determine the first signature parameter; where r is the first signature parameter, which constitutes the first part of the signature; mod is the modulo operation; If r equals 0, reselect the random integer k v ; If r is not equal to 0, use to determine the second signature parameter s; where s is the second signature parameter and forms the second part of the signature; and is the multiplicative inverse of the random integer k v modulo n; If s equals 0, reselect the random integer k v ; determine the first signature parameter r; Determine the signature SIGN based on the first signature parameter r and the second signature parameter s v as (r, s); Based on the original message M v , the signature SIGN v and the public key Pub i , the vehicle Vehicle i constructs a new message Msg; Msg is <M v , SIGN v , Pub i >, and sends the new message Msg: <M v , SIGN v , Pub i > to the roadside unit RSU j ; When the roadside unit RSU j receives the new message Msg, the roadside unit RSU j checks the validity of the signature SIGN v ; If either 1 ≤ r < n or 1 ≤ s < n is not satisfied, confirm that the signature (r, s) is invalid, and discard the received new message Msg; When 1 ≤ r < n and 1 ≤ s < n are satisfied, confirm that the signature (r, s) is valid, and the roadside unit RSU j Extract the key message M from the new message Msg v ; Based on the original message M v , using w = s -1 mod n, determine w; where w is the multiplicative inverse of the signature parameter s modulo n; s -1 is the multiplicative inverse of s modulo n; Based on the original message M v , the hash value e = h(M v ), and the multiplicative inverse w of the signature parameter s modulo n, determine the intermediate values u1 and u2 of the roadside unit RSU j according to u1 = e·w mod n and u2 = r·w mod n; Based on the intermediate values u1 and u2, determine the coordinates of the temporary point according to (x2, y2) = u1·G + u2·Pub i , where x2 is the abscissa of the temporary point; y2 is the ordinate of the temporary point; u1 is the intermediate value 1; u2 is the intermediate value 2; Pub i is the public key of the vehicle i Vehicle; Based on the abscissa x2 of the temporary point, the verification parameter v determined according to v = x2 mod n; where x2 is the abscissa of the temporary point; Extract r from the signature, and determine the detection result by judging whether v = r holds; If so, confirm that the detection result is the original message M v not tampered with during the transmission process, and the roadside unit accepts the original message M v ; Otherwise, confirm that the detection result is the original message M v has been tampered with during transmission, and discard the original message M v .
9. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that Based on the pseudo-identity identifier of the sender communication entity, according to the symmetric encryption algorithm and the quadruple stored in the trusted center TA, the trusted center TA completes the tracking of the true identity identifier of the false message sender, specifically including: If the sender uses a pseudo identity identifier PID m to complete malicious behavior, the receiver obtains the key K of the trusted center TA TA ; The receiver includes the roadside unit RSU j and the vehicle Vehicle i ; If the recipient is the roadside unit RSU j , then the roadside unit RSU j extracts parameters from the first memory; the parameters include the challenge C j of the roadside unit RSU j and the security parameter RK TA ; The roadside unit RSU j According to R j = PUF j (C j ) and determine the key K of the trusted center TA TA ; where C j is the challenge of the RSU j ; R j is the response of the RSU j ; PUF j () is the physically unclonable function embedded in the RSU j ; The roadside unit RSU j According to Determine the encrypted pseudo-identity identifier of the false message sender, and send the encrypted pseudo-identity identifier CPID m To the trusted center TA; where Is to use the key K of the trusted center TA To encrypt PID m For encryption operation; PID m Is the pseudo-identity identifier of the false message sender; After the Trusted Authority (TA) receives the encrypted pseudo-identity identifier CPID m , it performs a decryption operation to restore the pseudo-identity identifier PID of the false message sender m , where indicates that the Trusted Authority uses its key K TA to perform a decryption operation on CPID m ; Based on the pseudo identity identifier PID m Search respectively in the quadruple to determine the true identity ID of the malicious node m ; If the true identity ID of the perpetrator m is found in the quadruple of the vehicle Vehicle i , confirm that the true identity of the perpetrator comes from the vehicle Vehicle m ; If the true identity of the perpetrator is found in the quadruple of the roadside unit RSU j confirm that the true identity of the perpetrator comes from the roadside unit RSU m to complete the tracking of malicious nodes.
10. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that The communication entity adds the pseudo-identity identifier of the false message sender to the incremental pseudo-identity identifier revocation list of the communication entity to complete the revocation of the false message sender, specifically including: After receiving a false or malicious message, the communication entity generates a warning message M w ; The warning message M w includes the pseudo identity identifier PID of the malicious communication entity A ; The communication entity calculates the key K of the trusted authority TA TA ; when the communication entity is the roadside unit RSU j At this time, the RSU j extracts the triple (C j , PID j , RK TA ) from the first memory; by calculating R j =PUF j (C j ), determines the key K of TA TA ; when the communication entity is the vehicle Vehicle i At this time, the vehicle Vehicle i extracts the triple (C i , PID i , SK TA ) from the second memory, and by calculating R i =PUF i (C i ), determines the key K of TA TA ; Based on the key K of the trusted center TA TA , the communication entity encrypts the warning message M w to generate the encrypted warning message CM w , and sends the encrypted warning message CM w to the trusted center TA; wherein, the encrypted warning message CM w is The trusted center TA receives the encrypted warning message CM w and then broadcasts the encrypted warning message CM w to the communication entity; After the communication entity receives the broadcast message CM from the Trusted Authority (TA), w it decrypts the encrypted warning message CM TA using the key K w to obtain the original warning message M w ; where the original warning message M w is The communication entity determines a pseudo-identity identifier PID of the communication entity that sends the false or malicious message according to the original warning message M w ; A ; When receiving the message Msg1, the roadside unit RSU j checks whether the pseudo identity identifier PID of the sender i is in its incremental pseudo identity revocation list IPRL; If present, the roadside unit RSU j confirms the vehicle i as a revoked malicious vehicle and terminates the roadside unit RSU j from performing identity mutual trust authentication and session key negotiation with the vehicle i ; When receiving the message Msg2, the vehicle Vehicle i detects the PID j whether it is in its Incremental Pseudo-Identity Revocation List IPRL; If present, the vehicle i Verify the roadside unit RSU j As a revoked malicious roadside unit, terminate the vehicle i With the roadside unit RSU j Mutual trust authentication and session key negotiation of identities, complete the revocation of the malicious node; the malicious node includes the vehicle i Or the roadside unit RSU j .
Citation Information
Patent Citations
Authentication key negotiation method based on physical security and suitable for Internet of Vehicles environment
CN116707788A
Internet of vehicles efficient batch authentication key negotiation method based on signature
CN117098128A
Internet of vehicles authentication key negotiation method supporting conditional privacy protection
CN118890148A
Physical unclonable function based mutual authentication and key exchange
US20230032099A1
Cited By
Vehicle cross-domain authentication method, device and system
CN122294111A