Vehicle and roadside unit mutual authentication and key agreement method and device
By employing non-clonable functions, lightweight hash operations, and elliptic curve public-key cryptography algorithms in the Internet of Vehicles (IoV), two-way identity authentication and session key negotiation between vehicles and roadside units are achieved. This solves the problems of identity spoofing and information tampering in the IoV, improves authentication efficiency and privacy protection, and reduces the burden on the TA (Transportation Technology Provider).
Patent Information
- Application Number
- CN202510499683.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-04-21
AI Technical Summary
In the Internet of Vehicles (IoV), information exchange between vehicles and between vehicles and roads is vulnerable to security threats such as identity spoofing attacks, information interception, information tampering, and privacy leaks. Existing identity authentication and key negotiation methods are inefficient in high-speed, high-density vehicle scenarios, resulting in communication delays and excessive burden on the TA (Transportation Technology) system.
The system employs unclonable functions (PUF), lightweight hash operations, XOR operations, and elliptic curve public-key cryptography to achieve two-way authentication and session key negotiation between vehicles and roadside units. This reduces the number and length of authentication message interactions, avoids direct involvement of trusted centers, and uses pseudo-identity identifiers to track and revoke malicious communication entities.
It improves the authentication efficiency between vehicles and roadside units, reduces the number and length of authentication messages, lowers the burden on the TA, and enhances the privacy protection and anti-attack capabilities of the communicating entities.
Smart Images

Figure CN120378875B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the authentication of communication entities and message authentication in the Internet of Vehicles (IoV), and belongs to the field of IoV information security. In particular, it relates to a method and device for mutual trust authentication and key negotiation between vehicles and roadside units. Background Technology
[0002] In the Internet of Vehicles (IoV), vehicles and infrastructure exchange data and share information to update road conditions, traffic congestion, vehicle locations, and lane capacity, thereby improving traffic efficiency, preventing collisions and accidents, and ensuring traffic safety. However, the information exchange between vehicles and infrastructure uses public wireless channels, making it vulnerable to serious security threats such as identity spoofing, information interception, information tampering, fake message injection, and leakage of privacy and sensitive information. Currently, identity authentication and key negotiation are often used to address this issue. From a technical perspective, this requires the direct participation of a Trust Authority (TA) in authentication, achieving mutual trust authentication through information exchange between vehicles, TAs, and Roadside Units (RSUs). However, this authentication method involves a large number of exchanged messages and a longer number of bits, resulting in a longer time required to complete the mutual trust authentication, which is not conducive to the timely communication requirements of IoV scenarios. More seriously, in high-speed, high-density vehicle scenarios, the TA (Transmission Controller) bears a very heavy burden, easily causing a "single point of failure," severely reducing communication efficiency and hindering the vehicle-to-everything (V2X) environment characterized by high-speed vehicle movement and rapidly changing topologies. Furthermore, separating identity authentication from message authentication, and employing lightweight computation to combine V2X entity identity authentication and message authentication, so that the TA does not directly participate in authentication but is only used for vehicle and RUS (Roadside Access Control) registration and tracking of malicious communication entities, thereby reducing the number and length of message forwarding and improving authentication efficiency, is the primary design goal of this authentication method. Summary of the Invention
[0003] The purpose of this application is to provide a method for mutual trust authentication and session key negotiation between vehicles and roadside units, so as to solve the problem of low authentication efficiency between vehicles and roadside units.
[0004] Firstly, this application provides a method for mutual authentication and session key negotiation between a vehicle and a roadside unit, including:
[0005] Pre-installed Trusted Center TA Key K TA And embeds unclonable devices into communication entities; the communication entities include vehicles. i and roadside unit RSU j ;
[0006] When the communication entity receives the registration response, it stores the triple in the communication entity's memory; the triple includes the communication entity's challenge, the communication entity's pseudo-identity, and the communication entity's security parameters;
[0007] Based on the identity identifier, password, and timestamp of the communication entity, an authentication message is constructed using an elliptic curve public key cryptography algorithm. Through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message, the mutual trust authentication of the communication entity and the session key negotiation are realized.
[0008] After the identity mutual trust authentication and session key negotiation are completed, the receiving communication entity verifies the integrity of the received key messages;
[0009] Based on the pseudo-identity of the sending communication entity, and according to the symmetric encryption algorithm and the four-tuple stored by the Trusted Center (TA), the Trusted Center (TA) completes the tracking of the real identity of the fake message sender.
[0010] The communication entity adds the pseudo-identity identifier of the fake message sender to the communication entity's incremental pseudo-identity identifier revocation list, thereby completing the revocation of the fake message sender.
[0011] According to the vehicle-roadside unit mutual trust authentication and key negotiation method provided in this application, this application has the following technical effects:
[0012] This application provides a method, apparatus, and device for mutual trust authentication and key negotiation between a vehicle and a roadside unit, which utilizes a pre-set trusted central TA key K. TAThe process involves embedding an unclonable device into the communication entity; upon receiving a registration response, the communication entity stores the triplet in its memory; based on the communication entity's identity, password, and timestamp, an authentication message is constructed using an elliptic curve public-key cryptography algorithm; mutual trust authentication and session key negotiation are achieved through the interaction of authentication messages and the verification of parameters to be verified in the authentication messages; after identity mutual trust authentication and session key negotiation are completed, the receiving communication entity can verify the integrity of the received key messages; based on the pseudo-identity of the sending communication entity, and according to the symmetric encryption algorithm and the Trusted Center (TA) stored... The quadruple can track the identity of the sender of the fake message; the communication entity adds the fake message sender's pseudo-identity to its incremental pseudo-identity revocation list to complete the revocation of the fake message sender. The mutual trust authentication and key negotiation method between vehicles and roadside units adopts lightweight hash, XOR, symmetric encryption / decryption, and elliptic curve public key cryptography algorithms, which avoids the time and computational overhead of certificate generation, distribution and revocation processes, reduces the number and length of authentication message transmission, improves the authentication efficiency of vehicles and roadside units, and enhances the privacy protection function of the communication entity by adopting pseudo-identity transmission. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a flowchart illustrating a method for mutual trust authentication and key negotiation between a vehicle and a roadside unit according to an embodiment of this application.
[0015] Figure 2 Vehicle provided in one embodiment of this application i A diagram illustrating the registration process.
[0016] Figure 3 Roadside Unit (RSU) provided in one embodiment of this application j A diagram illustrating the registration process.
[0017] Figure 4 Vehicle provided in one embodiment of this application i and roadside unit RSU j Diagram illustrating mutual trust authentication and session key negotiation. Detailed Implementation
[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0019] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0020] This application employs Physical Unclonable Function (PUF), lightweight one-way hash operation (Hash), exclusive OR (XOR) operation, and elliptic curve public-key cryptography to achieve bidirectional authentication (or mutual trust authentication) between vehicles and Road Side Units (RSUs) in a vehicle-to-everything (V2X) environment. The advantages of existing technologies are mainly reflected in the following aspects: 1) They achieve bidirectional authentication between vehicles and RSUs, ensuring the legitimacy of the identities of both parties and preventing attackers from impersonating communication entities to send false messages. 2) They achieve negotiation of session keys between vehicles and RSUs. Sensitive messages such as vehicle identity and location are encrypted using the session key, and the receiver decrypts them using the session key, ensuring the confidentiality of the transmitted messages. 3) They achieve anonymity for communication entities. During the authentication message transmission process, both the sender and receiver interact anonymously, protecting user privacy and preventing tracking of communication entities in the V2X environment. 4) Prevents cloning and physical attacks. This method employs a non-clonable public key function (PUF), which offers advantages such as lightweight, low power consumption, high throughput, non-replicability, and difficulty for adversaries to forge or predict. Furthermore, it requires no additional storage space to store keys or random numbers. 5) Suitable for authentication and session key negotiation on resource-constrained devices. This method utilizes lightweight hash operations, XOR operations, elliptic curve public key cryptography algorithms, and the PUF function, resulting in low computational overhead. 6) This application integrates authentication and session key negotiation, reducing the number of authentication message interactions and the length of the interaction messages, thus decreasing authentication message transmission latency. 7) Mutual trust authentication between communicating parties does not require the direct involvement of a trusted third party (TA), significantly reducing the burden on the TA caused by authentication between densely communicating entities and lowering the likelihood of a single point of failure for the TA. 8) Enable the tracking and revocation of the identity of malicious communication entities. If a false or malicious message is detected, the pseudo-identity of the message sender can be sent to TA in an encrypted manner. Then TA can track and revoke the real identity of the false or malicious message sender in the access system to prevent malicious behavior by communication entities with legitimate identities.
[0021] like Figure 1 As shown in the figure, this application embodiment provides a method for mutual trust authentication and key negotiation between a vehicle and a roadside unit, which specifically includes the following steps.
[0022] S1: Pre-configured Trust Center TA Key K TA And embeds unclonable devices into communication entities; the communication entities include vehicles. i and roadside unit RSU j .
[0023] S2: After receiving the registration response, the communication entity stores the triple in its memory; the triple includes the communication entity's challenge, the communication entity's pseudo-identity, and the communication entity's security parameters.
[0024] S3: Based on the identity identifier, password, and timestamp of the communication entity, an authentication message is constructed using an elliptic curve public key cryptography algorithm. Through the interaction of the authentication message and the verification of the parameters to be verified in the authentication message, the mutual trust authentication of the communication entity and the session key negotiation are realized.
[0025] S4: After the identity mutual trust authentication and session key negotiation are completed, the receiving communication entity verifies the integrity of the received key message.
[0026] S5: Based on the pseudo-identity of the sending communication entity, and according to the symmetric encryption algorithm and the four-tuple stored by the Trusted Center (TA), the Trusted Center (TA) completes the tracking of the true identity of the fake message sender.
[0027] S6: The communication entity adds the pseudo-identity identifier of the fake message sender to the incremental pseudo-identity identifier revocation list of the communication entity, thereby completing the revocation of the fake message sender.
[0028] A method for mutual trust authentication and key negotiation between vehicles and roadside units is divided into four stages: system initialization, vehicle registration, roadside unit (RSU) registration, and mutual trust authentication and session key negotiation between vehicles and RSUs.
[0029] System initialization phase: The system administrator completes the TA key K TA Pre-built, non-clonable device PUF i In vehicle i Embedded within, and PUF (Physical Unclonable Device) j Roadside Unit RSU j Embedded within.
[0030] The system administrator selects the elliptic curve equation y 2 =x 3 Given the expression +ax+b(mod p), where a and b are elliptic curve parameters and p is a large prime number, find the discriminant 4a. 3 +27b 2 ≠0 (mod p) to ensure that the elliptic curve has no singularities.
[0031] Furthermore, in an exemplary embodiment, S2 can be replaced by the following steps.
[0032] S201: The communicating entity selects its own identity and password and generates a binary string.
[0033] S202: Using the binary string as a challenge, determine the response based on the non-clonable device embedded in the communication entity, and use the response as the private key of the communication entity.
[0034] Vehicle i Select your identity ID i and key PW i Generate binary string C i As a challenge, and by embedding it in Vehicle i Unclonable Functions (PUFs) i Receive response R i =PUF i (C i As a Vehicle i The private key.
[0035] S203: Based on the identity identifier, the password, and the private key, calculate the registration request message and send the registration request message to the Trusted Center (TA).
[0036] The Vehicle i Calculate R i =PUF i (C i ) and PID i =h(ID) i ||PW i ||R i ), PID i As its pseudo-identity, and through a secure channel, the registration request message ReqV: <ID i ,PID i C i ,R i > Send to TA.
[0037] S204: When the Trusted Center (TA) receives the registration request message ReqV, it determines the identity identifier ID. i Does it exist?
[0038] If so, let the communication entity Vehicle i Choose a new identity.
[0039] If not, the Trusted Center (TA) calculates the registered communication entity Vehicle. i The identity is obfuscated, and the four-tuple is stored in the database of the Trusted Center (TA); the four-tuple includes the communication entity Vehicle.i Identity identifier, the communication entity Vehicle i The pseudo-identity identifier, the communication entity Vehicle i The challenges and responses of the communicating entities.
[0040] S205: The Trusted Center (TA) communicates with the registered communication entity Vehicle through a secure channel. i Send a registration response, which is a confused identity identifier of the registered communication entity calculated by the Trusted Center (TA).
[0041] S206: When registering the communication entity Vehicle i Upon receiving the registration response, the key and triplet of the Trusted Center (TA) are determined, and the triplet is stored in the registered communication entity, Vehicle. i In the memory; the triple includes the registered communication entity Vehicle. i The challenge, the registered communication entity Vehicle i The pseudo-identity identifier and the registered communication entity Vehicle i Safety parameters.
[0042] like Figure 2 As shown, Vehicle i Received registration response ResV:<MID i After >, calculate Then store the triplet (C i ,PID i SK TA ) in its memory.
[0043] like Figure 3 As shown, the roadside unit (RSU) j Select your identity ID j and PW j Generate binary string C j As a challenge, and by embedding it in RSU j Unclonable Functions (PUFs) j Obtain the response output R j =PUF j (C j ), and R j As its private key. Then, RSU j Calculate PID j =h(ID) j ||PW j ||R j And send a registration request ReqR to TA through a secure channel; ReqR is <IDj ,PID j C j ,R j >.
[0044] After receiving the registration request (ReqR), the TA first checks the ID. j Does it exist? If ID j If it has already been used, notify the RSU. j Choose a new identity identifier; otherwise, calculate the TA. And store 4-tuples (ID) j ,PID j C j ,R j ) in its database, and then through a secure channel to the RSU j Send registration response ResR:<MID j >.
[0045] RSU j Received registration response ResR:<MID j After >, calculate Then store the triplet (C j ,PID j ,RK TA ) in its memory.
[0046] Furthermore, in an exemplary embodiment, S3 can be replaced by the following steps.
[0047] S301: Input the vehicle i Identity ID i Password PW i Using the timestamp t1, and the elliptic curve public-key cryptography algorithm, we obtain the message Msg1.
[0048] S302: When the roadside unit RSU j Upon receiving the message Msg1, the validity of the timestamp t1 is determined, and the verification parameter A in the message Msg1 is used as a reference. i Complete the vehicle i Authentication, determining the session key The parameter to be verified, A i h(PID) i ||PID j ||K TA ||t1); where h() is a one-way hash function; PID i For the vehicle i Pseudo-identity identifier; PID j For the roadside unit RSU jFalse identity marker; K TA t1 is the key for TA; t1 is the timestamp when the message Msg1 was sent.
[0049] S303: The roadside unit RSU j Generate timestamp t2, extract the triplet stored in the first memory, and complete the verification of the parameter A1 to be verified and the session key. The calculation is performed, and the authentication message Msg2 is constructed according to the elliptic curve public key cryptography algorithm; the first memory is the roadside unit RSU. j The memory.
[0050] S304: When the vehicle i Upon receiving the message Msg2, the validity of the timestamp t2 is determined, and the verification parameter B in the message Msg2 is used as a basis. j Complete the roadside unit (RSU) j Identity authentication to determine the vehicle. i Session key The parameter to be verified, B j h(PID) j ||PID i ||K TA ||t2); where t2 is the timestamp when the message Msg2 was sent.
[0051] Specifically, S301 includes:
[0052] S3011: The vehicle i Enter its identity ID i and password PW i And retrieve the vehicle from the second memory. i The triplet; the triplet is (C i ,PID i SK TA ); where C i For the vehicle i Challenges; PID i For the vehicle i False identity markers; SK TA For the vehicle i The safety parameters; the second memory is the vehicle. i The memory.
[0053] S3012: Based on the triplet, utilize the embedded non-cloning function PUF i (), determine the vehiclei Response R i =PUF i (C i ), and according to Determine the vehicle i fake identity markers Among them, R i For the vehicle i The response.
[0054] S3013: Judgment Whether it is valid or not.
[0055] If not, confirm the vehicle. i User authentication failed, vehicle prohibited. i Log in to terminate the current identity mutual trust authentication and session key negotiation.
[0056] If so, the vehicle i Generate the current timestamp t1, and based on... Determine the key K of the Trusted Center TA TA .
[0057] S3014: Based on the key K TA According to A i =h(PID) i ||PID j ||K TA ||t1), determine the vehicle i The parameter A to be verified i Where h() is the hash operation; A i For the vehicle i Parameters to be verified.
[0058] S3015: Based on the vehicle i Response R i Based on the elliptic curve public-key cryptography algorithm, the vehicle is determined. i Public key Pub i .
[0059] S3016: Based on the public key Pub i The vehicle i To the roadside unit RSU j Send message Msg1; where Msg1 is <PID i A i Pub i ,t1>.
[0060] like Figure 4 As shown, the user inputs Vehicle i Identity ID i and password PW i and retrieve C from its memory i PID i and SK TA Then calculate R i =PUF i (C i )and Subsequent inspection If the two are not equal, it indicates that the user's identity authentication has failed, and the system terminates the current identity mutual trust authentication and session key negotiation process; otherwise, the Vehicle... i Generate the current timestamp t1, calculate A i =h(PID) i ||PID j ||K TA ||t1), and calculate its public key Pub based on the elliptic curve public-key cryptography algorithm. i =R i ·G, then to RSU j Send message Msg1: <PID i A i Pub i ,t1>.
[0061] Specifically, S302 includes:
[0062] S3021: When the roadside unit RSU j Upon receiving the message Msg1, check the validity of the timestamp t1.
[0063] S3022: If the absolute value of the difference between the timestamp t1 and the current time exceeds a preset value, the timestamp t1 is confirmed to be invalid, and the current identity mutual trust authentication and session key negotiation process is terminated.
[0064] S3023: If the absolute value of the difference between the timestamp t1 and the current system time does not exceed the preset value, the timestamp t1 is confirmed to be valid.
[0065] S3024: The roadside unit RSU j Retrieve the Roadside Unit (RSU) from the first memory. j Challenge C j PID (Pseudo-identity identifier) j and safety parameter RK TA .
[0066] S3025: Based on the embedded unclonable function PUFj (), determine the roadside unit RSU j Response R j =PUF j (C j ); where C j For the roadside unit RSU j The challenge.
[0067] S3026: According to Determine the key K of the Trusted Center TA TA and according to Calculate the parameters to be verified
[0068] S3027: Inspection Whether it is valid or not.
[0069] If not, confirm the vehicle. i If identity authentication fails, the current identity mutual trust authentication and session key negotiation process will be terminated.
[0070] If so, the roadside unit (RSU) j Confirm the vehicle i The legitimacy of identity, and according to Determine the session key in, For the roadside unit RSU j The calculated session key; R j For the roadside unit RSU j Response; Pub i For the vehicle i The public key; R i For the vehicle i The response, where G is a public base point on the elliptic curve.
[0071] RSU j Upon receiving message Msg1, the validity of t1 is first checked. If the absolute value of the time difference between t1 and the current system time exceeds a preset value, the current identity mutual trust authentication and session key negotiation process is terminated; otherwise, t1 is considered valid, and RSU is initiated. j Extract C from its memory j PID j and RK TA Calculate R j =PUF j (C j ), as well as Then check If the two are not equal, it indicates that the vehiclei If identity authentication fails, the system terminates the current identity mutual trust authentication and session key negotiation process; otherwise, the Vehicle... i Their identities were verified, and then the RSU... j Calculate session key
[0072] Specifically, S303 includes:
[0073] S3031: The roadside unit RSU j Generate timestamp t2.
[0074] S3032: According to B j =h(PID) j ||PID i ||K TA ||t2) Determine the roadside unit RSU j The parameter B to be verified j , where PID j For the roadside unit RSU j Pseudo-identity identifier; PID i For the vehicle i False identity marker; K TA t2 is the key of the Trusted Center (TA); t2 is the timestamp; B j For the roadside unit RSU j The parameters to be verified.
[0075] S3033: According to Pub j =R j ·G determines the roadside unit RSU j Public key Pub j Where G is a public base point on the elliptic curve.
[0076] S3034: Based on the roadside unit RSU j PID (Pseudo-identity identifier) j The roadside unit (RSU) j The parameter B to be verified j The roadside unit (RSU) j Response R j and the timestamp t2, and Pub j =R j ·G constructs message Msg2 and sends it to the vehicle. i Send message Msg2; where Msg2 is <PID j B j Pub j ,t2>.
[0077] Specifically, S304 includes:
[0078] S3041: When the vehicle i Upon receiving the message Msg2, determine the validity of the timestamp t2.
[0079] S3042: If the absolute value of the difference between the timestamp t2 and the current system time exceeds a preset value, the timestamp t2 is confirmed to be invalid, and the current identity mutual trust authentication and session key negotiation are terminated.
[0080] S3043: If the absolute value of the difference between the timestamp t2 and the current system time does not exceed the preset value, the timestamp t2 is confirmed to be valid.
[0081] S3044: According to Determine the roadside unit (RSU) j Parameters to be verified
[0082] S3045: Judgment Whether it is valid or not.
[0083] If not, confirm the roadside unit (RSU). j If identity authentication fails, the current identity mutual trust authentication and session key negotiation process will be terminated.
[0084] If so, confirm the Roadside Unit (RSU). j Verify the legitimacy of the identity and confirm the verification result.
[0085] S3046: Based on the verification results, according to Calculate the vehicle i Session key
[0086] Furthermore, in an exemplary embodiment, S4 can be replaced by the following steps.
[0087] S401: The vehicle i According to e = h(M) v Determine the hash value e of the key message; where M v This is key information.
[0088] S402: Based on the hash value of the key message, let the vehicle... i Select a random integer k v The random integer k v Satisfying 1≤k v <n, where n is the order of the elliptic subgroup.
[0089] S403: Based on the elliptic curve public-key cryptography algorithm, using (x1,y1)=k v ·G, determine the vehicle i The temporary point; where x1 is the x-coordinate of the temporary point; y1 is the y-coordinate of the temporary point.
[0090] S404: The vehicle i Take the x-coordinate x1 of the temporary point, and use r = x1 mod n to determine the parameter r; where r is the first signature parameter, which constitutes the first part of the signature; mod is the modulo operation.
[0091] If r equals 0, the random integer k is selected again. v .
[0092] If r is not equal to 0, use Determine the second signature parameter s; where s is the second signature parameter, constituting the second part of the signature; For the random integer k v Multiplicative inverse modulo n.
[0093] S405: If s equals 0, select the random integer k again. v Determine the first signature parameter r.
[0094] S406: Determine the signature SIGN based on the first signature parameter r and the second signature parameter s. v Let (r,s) be the value.
[0095] S407: Based on the key message M v The signature SIGN v and public key Pub i The vehicle i Construct a new message Msg; Msg is <M v SIGN v Pub i >, and the new message Msg:<M v SIGN v Pub i >Sent to the roadside unit RSU j .
[0096] S408: When the roadside unit RSU j Upon receiving the new message Msg, the roadside unit (RSU) j Check the signature SIGN v The effectiveness.
[0097] S409: If either 1≤r<n or 1≤s<n is not satisfied, the signature (r,s) is deemed invalid, and the received new message Msg is discarded.
[0098] If 1 ≤ r < n and 1 ≤ s < n, then the signature (r, s) is confirmed to be valid, and the roadside unit (RSU) is confirmed to be valid. j Extract the key message M from the new message Msg. v .
[0099] S410: Based on the key message M v Using w=s -1 mod n, determine w; where w is the multiplicative inverse of the signature parameter s modulo n; s -1 It is the multiplicative inverse of s modulo n.
[0100] S411: Based on the key message M v The hash value e = h(M) v The roadside unit (RSU) is determined based on the multiplicative inverse w of the signature parameter s modulo n, and u1 = e·w mod n and u2 = r·w mod n. j The intermediate values u1 and u2.
[0101] S412: Based on the intermediate values u1 and u2, according to (x2,y2)=u1·G+u2·Pub i Determine the coordinates of the temporary point; where x2 is the x-coordinate of the temporary point; y2 is the y-coordinate of the temporary point; u1 is the intermediate value 1; u2 is the intermediate value 2; Pub i For the vehicle i The public key.
[0102] S413: Based on the abscissa x2 of the temporary point, the verification parameter v is determined according to v = x2 mod n; where x2 is the abscissa of the temporary point.
[0103] S414: Extract r from the signature, determine whether v = r is true, and determine the detection result.
[0104] If so, confirm that the detection result is the key message M. v The key message M is received by the roadside unit without being tampered with during transmission. v .
[0105] If not, confirm that the detection result is the key message M. v The critical message M was tampered with during transmission and was discarded. v .
[0106] The vehicle iThe integrity check for sending critical messages specifically includes the following steps:
[0107] Step 1.1: Vehicle i Calculate the key message M to be sent. v The hash value e, where e = h(M) v ).
[0108] Step 1.2: Vehicle i Select a random integer k v Make it satisfy 1≤k v <n.
[0109] Step 1.3: Vehicle i Calculate a temporary point (x1, y1) = k v ·G.
[0110] Step 1.4: Calculate and generate the signature. Vehicle i First, take the coordinate value of x1 and calculate r = x1 mod n. If r = 0, then choose k again. v Return to step 1.3; otherwise, Vehicle i calculate in It is k v Multiplicative inverse modulo n. If s = 0, then k is chosen again. v Return to step 1.3.
[0111] Step 1.5: Vehicle i Based on the calculated r and s, generate the signature SIGN. v =(r,s), using key message M v Signature SIGN v =(r,s) and its public key Pub i Construct a new message Msg: <M v SIGN v Pub i >, then send Msg to RSU j .
[0112] Step 1.6: RSU j Upon receiving the message Msg, first check the validity of the signature. If 1 ≤ r < n and 1 ≤ s < n, then the signature is valid, and proceed to Step 1.7; otherwise, the signature is invalid, and the received message Msg is discarded.
[0113] Step 1.7: RSU j Extract key message M from Msg v And calculate e = h(M)v ), w = s -1 mod n, where s -1 It is the multiplicative inverse of s modulo n.
[0114] Step 1.8: RSU j Calculate the intermediate values u1 and u2, where u1 = e·w mod n and u2 = r·w mod n. Then calculate the temporary point (x2, y2) = u1·G + u2·Pub. i .
[0115] Step 1.9: RSU j Take the coordinates of x2, calculate v = x2 mod n, and then from the received signature SIGN v Extract r from (r,s), then check if v = r. If they are equal, it indicates that the key message M is true. v The message was not tampered with during transmission, and the key message M was received. v If the two are not equal, it indicates that the key message M... v If the received critical message M is tampered with during transmission, it will be discarded. v .
[0116] The roadside unit RSU j Send key message M R The integrity check specifically includes the following steps:
[0117] Step 2.1: RSU j Calculate the key message M to be sent. R The hash value e, where e = h(M) R );
[0118] Step 2.2: RSU j Select a random integer k R Make it satisfy 1≤k R <n.
[0119] Step 2.3: RSU j Calculate a temporary point (x1, y1) = k R ·G.
[0120] Step 2.4: RSU j Take the coordinate value of x1, calculate r = x1 mod n. If r = 0, then choose k again. R Return to step 2.3; otherwise, RSU. j calculate in It is k R Multiplicative inverse modulo n. If s = 0, then k is chosen again.R Return to Step 2.3.
[0121] Step 2.5: RSU j Based on the calculated r and s, generate the signature SIGN. R =(r,s), using the key message M R Signature SIGN R =(r,s) and its public key Pub j Construct a new message Msg: <M R SIGN R Pub j >, then send Msg to Vehicle i .
[0122] Step 2.6: Vehicle i Upon receiving the message Msg, first check the validity of the signature. If 1 ≤ r < n and 1 ≤ s < n, then the signature is valid, and proceed to Step 2.7; otherwise, the signature is invalid, and the received message Msg is discarded.
[0123] Step 2.7: Vehicle i Extract key message M from Msg R And calculate e = h(M) R ), w = s -1 mod n, where s -1 It is the multiplicative inverse of s modulo n.
[0124] Step 2.8: Vehicle i Calculate the intermediate values u1 and u2, where u1 = e·w mod n and u2 = r·w mod n. Then calculate the temporary point (x2, y2) = u1·G + u2·Pub. j .
[0125] Step 2.9: Vehicle i Take the coordinates of x2, calculate v = x2 mod n, and then from the received signature SIGN R Extract r from (r,s), then check if v = r. If they are equal, it indicates that the key message M is true. R The key message M was not tampered with during transmission and was received. R If the two are not equal, it indicates that the key message M... R If the received critical message M is tampered with during transmission, it will be discarded. R .
[0126] Furthermore, in an exemplary embodiment, S5 can be replaced by the following steps.
[0127] S501: If the sender uses a fake identity identifier (PID) m After committing malicious acts, the receiver obtains the key K of the trusted center TA. TA The receiver includes the roadside unit (RSU). j and the vehicle i .
[0128] S502: If the receiver is the roadside unit (RSU) j Then the roadside unit RSU j Parameters are extracted from the first memory; the parameters include the roadside unit (RSU). j Challenge C j and safety parameter RK TA .
[0129] S503: The roadside unit RSU j According to R j =PUF j (C j )and Determine the key K of the Trusted Center TA TA Among them, C j For RSU j The challenge; R j For RSU j Response; PUF j () is for embedding into RSU j Unclonable functions in [the context of the text].
[0130] S504: The roadside unit RSU j according to The encrypted pseudo-identity identifier of the sender of the fake message is determined, and the encrypted pseudo-identity identifier is sent to the Trusted Center (TA); wherein, CPID m This is an encrypted pseudo-identity identifier; To utilize the key K of the trusted center TA For PID m Perform encryption operations; PID m It serves as a false identity identifier for those who send fake messages.
[0131] S505: The Trusted Center (TA) receives the encrypted pseudo-identity identifier (CPID). m Then, execute Decryption operation to restore the pseudo-identity PID of the sender of the fake message. m ,in, This indicates that the trusted center uses its key K TA For CPID m Perform the decryption operation.
[0132] S506: Based on the pseudo-identity identifier PID m Search within each of the four tuples to determine the true identity ID of the malicious node. m .
[0133] S507: If the true identity ID of the perpetrator is... m The vehicle i The perpetrator was found in the quadruple set, confirming their true identity as a vehicle. m .
[0134] S508: If the true identity of the perpetrator is in the roadside unit (RSU) j The perpetrator was found in the quadruple, confirming their true identity as a roadside unit (RSU). m This completes the tracking of malicious nodes.
[0135] Furthermore, in an exemplary embodiment, S6 can be replaced by the following steps.
[0136] S601: After receiving a false or malicious message, the communication entity generates a warning message M. w The warning message M w Including the spoofed identifier (PID) of malicious communication entities A .
[0137] S602: The communication entity calculates the key K of the trusted center TA. TA When the communication entity is the roadside unit (RSU) j At that time, the RSU j Extract the triplet (C) from the first memory. j ,PID j ,RK TA ); by calculating R j =PUF j (C j ), Determine the key K of TA TA When the communication entity is the vehicle i At that time, the vehicle i Extract the triplet (C) from the second memory. i ,PID i ,SKTA), by calculating R i =PUF i (C i ), Determine the key K of TA TA .
[0138] S603: Key K based on the trusted center TA TA The communication entity responds to the warning message M w Encryption is performed, and an encrypted warning message CM is generated. w and the encrypted warning message CM w Send to the Trusted Center (TA); wherein the encrypted warning message CM w for
[0139] S604: The Trusted Center (TA) receives the encrypted warning message CM w Then, the encrypted warning message CM w Broadcast to the communication entity.
[0140] S605: The communication entity receives the broadcast message CM from the trusted center TA. w Then, based on key K TA The encrypted warning message CM w Decryption yields the original warning message M. w ; wherein, the original warning message M w for
[0141] S606: The communication entity, based on the original warning message M w Determine the pseudo-identity identifier (PID) of the communication entity that sent the false or malicious message. A .
[0142] S607: Upon receiving the message Msg1, the roadside unit RSU j Check the sender's pseudo-identity PID i Whether it is in the Incremental Pseudo-Identity Revocation List (IPRL).
[0143] S608: If so, the roadside unit RSU j Confirm the vehicle i For malicious vehicles that have been withdrawn, the Roadside Unit (RSU) is terminated. j With the vehicle i Identity mutual trust authentication and session key negotiation.
[0144] S609: Upon receiving the message Msg2, the vehicle i Detect the PID j Whether it is in its incremental pseudo-identity revocation list (IPRL).
[0145] S610: If the vehicle is... iConfirm the Roadside Unit (RSU) j For malicious roadside units to be withdrawn, terminate the vehicle. i With the roadside unit RSU j The identity mutual trust authentication and session key negotiation are used to complete the revocation of the malicious node; the malicious node includes the vehicle. i or the roadside unit RSU j .
[0146] The tracking and revocation of malicious nodes specifically includes:
[0147] Step 3.1: After receiving a false or malicious message, the communication entity generates a warning message M. w The communication entity includes a roadside unit (RSU). j and vehicles i The warning message M w Includes a fake identifier (PID) of a malicious communication entity. A .
[0148] Step 3.2: The communication entity calculates the key K of the trusted center TA. TA When the communication entity is the roadside unit (RSU) j At that time, the RSU j Extract the triplet from its memory (C j ,PID j ,RK TA ), by calculating R j =PUF j (C j ), Determine the key K of TA TA When the communication entity is a vehicle i At that time, the vehicle i Extract the triplet from its memory (C i ,PID i SK TA ), by calculating R i =PUF i (C i ), Determine the key K of TA TA .
[0149] Step 3.3: The communication entity (which can be a roadside unit, RSU) j It can also refer to a vehicle. i The key K of the trusted center TA obtained through computation TA For the warning message M wEncryption is performed, and an encrypted warning message CM is generated. w and CM w Send to the Trusted Center (TA), where
[0150] Step 3.4: The Trusted Center (TA) receives the encrypted warning message CM. w , CM w Broadcast to the communication entity, which includes a roadside unit (RSU). j and vehicles i .
[0151] Step 3.5: Receive TA's broadcast message CM w Then, the communication entity uses the calculated TA key K. TA Regarding the encrypted warning message CM w Decryption yields the original warning message M. w ,in
[0152] Step 3.6: The communication entity, based on the original warning message M w To identify the pseudo-identity (PID) of the communication entity that sent the false or malicious message. A And add it to the incremental pseudo-identity revocation list (IPRL) of the communication entity.
[0153] Step 3.7: If the message Msg1: <PID is received i A i Pub i ,t1>, the roadside unit RSU j Check the sender's pseudo-identity ID (PID) i Whether in the roadside unit RSU j In the incremental pseudo-identity revocation list IPRL; if the message Msg2: <PID is received j B j Pub j ,t2>, the vehicle i Check the sender's pseudo-identity ID (PID) j Whether in the vehicle i In the incremental pseudo-identity revocation list (IPRL).
[0154] Step 3.8: If the check result is positive, the message receiver terminates the mutual trust authentication and session key negotiation between the message sender and the recipient, thus completing the revocation of the identity of the false or malicious message sender.
[0155] For ease of explanation of this application, the identifiers used are defined as shown in Table 1:
[0156] Table 1 Identifier Definitions
[0157]
[0158]
[0159] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for mutual trust authentication and key negotiation between a vehicle and a roadside unit, characterized in that, The vehicle-roadside unit mutual trust authentication and key negotiation method includes: Pre-installed Trusted Center TA Key and embeds unclonable devices into communication entities; the communication entities include vehicles. and roadside units ; When the communication entity receives the registration response, it stores the triple in the communication entity's memory; the triple includes the communication entity's challenge, the communication entity's pseudo-identity, and the communication entity's security parameters; Based on the identity identifier, password, and timestamp of the communication entity, an authentication message is constructed using an elliptic curve public key cryptography algorithm. Through the interaction of this authentication message and the verification of the parameters to be verified within it, mutual trust authentication and session key negotiation of the communication entity are achieved. Specifically, this includes: inputting the vehicle... Identity identifier ,password and timestamp The message is obtained using the elliptic curve public-key cryptography algorithm. When the roadside unit Received the message Then, determine the timestamp. The validity of the message, and based on the parameters to be verified in the message Msg1. Complete the vehicle Authentication, determining the session key The parameter to be verified for ;in, It is a one-way hash function; For the vehicle Fake identity markers; For the roadside unit Fake identity markers; This is TA's key; The timestamp when the message Msg1 was sent; the roadside unit Generate timestamp Extract the triples stored in the first memory to complete the verification of the parameter to be verified. Authentication and session key The calculation is performed, and an authentication message is constructed based on the elliptic curve public-key cryptography algorithm. The first memory is the roadside unit. The memory; when the vehicle Received the message Then, determine the timestamp. The validity of the message, and based on the parameters to be verified in the Msg2 message. Complete the roadside unit Identity authentication to determine the vehicle Session key The parameter to be verified for ;in, The timestamp when the message Msg2 was sent; After the identity mutual trust authentication and session key negotiation are completed, the receiving communication entity verifies the integrity of the received key messages; Based on the pseudo-identity of the sending communication entity, and according to the symmetric encryption algorithm and the four-tuple stored by the Trusted Center (TA), the Trusted Center (TA) completes the tracking of the real identity of the fake message sender. The communication entity adds the pseudo-identity identifier of the fake message sender to the communication entity's incremental pseudo-identity identifier revocation list, thereby completing the revocation of the fake message sender.
2. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, After receiving the registration response, the communication entity stores the triple in its memory, specifically including: The communicating entity selects its own identity and password, and generates a binary string; The binary string is used as a challenge to determine the response based on the non-clonable device embedded in the communication entity, and the response is used as the private key of the communication entity. Based on the identity identifier, the password, and the private key, calculate the registration request message and send the registration request message to the Trusted Center (TA); When the Trusted Center (TA) receives the registration request message, it determines whether the identity identifier exists. If so, instruct the communication entity to reselect an identity identifier; If not, the Trusted Center (TA) calculates the obfuscated identity of the registered communication entity and stores the quadruple in the TA's database; the quadruple includes the communication entity's identity, the communication entity's pseudo-identity, the communication entity's challenge, and the communication entity's response; The Trusted Center (TA) sends a registration response to the registered communication entity through a secure channel. The registration response is a confused identity identifier of the registered communication entity calculated by the Trusted Center (TA). When the registered communication entity receives the registration response, it determines the key and triple of the Trusted Center (TA) and stores the triple in the registered communication entity's memory; the triple includes the challenge of the registered communication entity, the pseudo-identity of the registered communication entity, and the security parameters of the registered communication entity.
3. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, Input the vehicle Identity identifier ,password and timestamp The message is obtained using the elliptic curve public-key cryptography algorithm. Specifically, it includes: The vehicle Enter their identity information and password And retrieve the vehicle from the second memory. The triplet; the triplet is ;in, For the vehicle The challenges; For the vehicle Fake identity markers; For the vehicle The safety parameters; the second memory is the vehicle's... Memory; Based on the triples, using the embedded non-cloning function Determine the vehicle response and according to Determine the vehicle fake identity ;in, For the vehicle The response; judge Is it valid? If not, confirm the vehicle. User authentication failed; the vehicle is prohibited. Log in to terminate the current identity mutual trust authentication and session key negotiation; If so, the vehicle Generate current timestamp and according to Determine the key of the Trusted Center (TA) ; Based on the key ,according to Determine the vehicle Parameters to be verified ;in, This is a hash operation; For the vehicle Parameters to be verified; Based on the vehicle response The vehicle is determined using the elliptic curve public-key cryptography algorithm. public key ; Based on the public key The two vehicles To the roadside unit Send message The for .
4. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, When the roadside unit Received the message Then, determine the timestamp. The validity of the message, and based on the parameters to be verified in the message Msg1. Complete the vehicle Authentication, determining the session key Specifically, it includes: When the roadside unit Received the message Then, check the timestamp. Validity; If the timestamp If the absolute value of the time difference with the current time exceeds a preset value, the timestamp is confirmed. Invalid; terminate the current identity mutual trust authentication and session key negotiation process. If the timestamp The absolute value of the time difference with the current system time does not exceed a preset value, confirming the timestamp. efficient; The roadside unit Retrieve the roadside unit from the first memory. Challenges False identity markers and safety parameters ; Based on the embedded non-cloning function Determine the roadside unit response ;in, For the roadside unit The challenges; according to Determine the key of the Trusted Center (TA). and according to Calculate the parameters to be verified ; Detection Is it valid? If not, confirm the vehicle. If identity authentication fails, the current identity mutual trust authentication and session key negotiation process will be terminated. If so, the roadside unit Confirm the vehicle The legitimacy of identity, and according to Determine the session key ;in, For the roadside unit The calculated session key; For the roadside unit The response; For the vehicle The public key; For the vehicle The response, G is a public base point on the elliptic curve.
5. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, The roadside unit Generate timestamp Extract the triples stored in the first memory to complete the verification of the parameter to be verified. Authentication and session key The calculation is performed, and an authentication message is constructed based on the elliptic curve public-key cryptography algorithm. Specifically, it includes: The roadside unit Generate timestamp ; according to Determine the roadside unit Parameters to be verified ,in, For the roadside unit Fake identity markers; For the vehicle Fake identity markers; The key for the Trusted Center (TA); For timestamps; For the roadside unit The parameters to be verified; according to Determine the roadside unit public key Where G is a public base point on the elliptic curve; Based on the roadside unit fake identity The roadside unit Parameters to be verified The roadside unit public key and the timestamp ,according to Build message and to the vehicle Send message The for .
6. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, When the vehicle Received the message Then, determine the timestamp. The validity of the message, and based on the parameters to be verified in the Msg2 message. Complete the roadside unit Identity authentication to determine the vehicle Session key Specifically, it includes: When the vehicle Received the message Then, determine the timestamp. Validity; If the timestamp If the absolute value of the time difference with the current system exceeds a preset value, the timestamp is confirmed. If invalid, terminate the current identity mutual trust authentication and session key negotiation; If the timestamp The absolute value of the time difference with the current system time does not exceed a preset value, confirming the timestamp. efficient; according to Determine the roadside unit Parameters to be verified ; judge Is it valid? If not, confirm the roadside unit. If identity authentication fails, the current identity mutual trust authentication and session key negotiation process will be terminated. If so, confirm the roadside unit. Verify the legitimacy of the identity and confirm the verification result; Based on the verification results, according to Calculate the vehicle Session key .
7. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, After the identity mutual trust authentication and session key negotiation are completed, the receiving communication entity verifies the integrity of the received key messages, specifically including: The vehicle ,according to Determine the hash value e of the key message; where, It is a one-way hash function; This is key information; Based on the hash value of the key message, the vehicle... Select a random integer The random integer satisfy , where n is the order of the elliptic curve subgroup; Based on the elliptic curve public-key cryptography algorithm, using Determine the vehicle Temporary points; among them, The x-coordinate of the temporary point; The ordinate of the temporary point; The vehicle Take the x-coordinate of the temporary point ,use The first signature parameter is determined; where r is the first signature parameter, constituting the first part of the signature; mod is the modulo operation; If r equals 0, the random integer is selected again. ; If r is not equal to 0, use Determine the second signature parameter s; where s is the second signature parameter, constituting the second part of the signature; The random integer Multiplicative inverse modulo n; For the vehicle The response; If s equals 0, the random integer is selected again. Determine the first signature parameter r; Based on the first signature parameter r and the second signature parameter s, the signature is determined. for ; Based on the key information The signature and public key The vehicle Construct a new message Msg; Msg is and the new message Send to the roadside unit ; When the roadside unit Received the new message Then, the roadside unit Check the signature Validity; If not satisfied or Any one of them, confirm the signature Invalid; discard the received new message Msg. If satisfied and At that time, confirm the signature. Effective, the roadside unit Extract the key message from the new message Msg. ; Based on the key information ,use Determine w; where w is the multiplicative inverse of the signature parameter s modulo n; yes Multiplicative inverse modulo n; Based on the key information hash value And the multiplicative inverse w of the signature parameter s modulo n, according to and Determine the roadside unit median value and ; Based on the intermediate value and ,according to Determine the coordinates of the temporary point; where, The x-coordinate of the temporary point; The ordinate of the temporary point; The median value is 1; The median value is 2; For the vehicle The public key; Based on the x-coordinate of the temporary point ,according to Determined verification parameters ;in, The x-coordinate of the temporary point; Extract r from the signature and determine... To determine whether the test results are valid, we need to verify the validity of the test. If so, confirm that the detection result is the key message. The key message was received by the roadside unit without being tampered with during transmission. ; If not, confirm that the detection result is the key message. The critical message was tampered with during transmission and was discarded. .
8. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, Based on the pseudo-identity of the sending communication entity, and according to the symmetric encryption algorithm and the four-tuple stored by the Trusted Center (TA), the Trusted Center (TA) completes the tracking of the true identity of the fake message sender, specifically including: If the sender uses a fake identity After committing malicious acts, the receiver obtains the key from the Trusted Center (TA). The receiver includes the roadside unit. and the vehicle ; If the receiver is the roadside unit Then the roadside unit Parameters are extracted from the first memory; the parameters include the roadside unit. Challenges and safety parameters ; The roadside unit according to and Determine the key of the Trusted Center (TA). ;in, for The challenges; for The response; For embedding Unclonable functions in; The roadside unit according to Determine the encrypted pseudo-identity identifier of the sender of the fake message, and then... Send to the Trusted Center (TA); where, To utilize the keys of a trusted center right Perform encryption operations; A fake identity for the sender of false messages; The trusted center (TA) receives the encrypted pseudo-identity identifier. Then, execute Decryption operation to restore the fake identity of the sender of the fraudulent message. ,in, This indicates that the trusted center utilizes its keys. right Perform the decryption operation; Based on the pseudo-identity identifier Search within each of the four tuples to determine the true identity of the malicious node. ; If the true identity of the perpetrator In the vehicle The perpetrator was found in the quadruple set, confirming their true identity as originating from the vehicle. ; If the true identity of the perpetrator is in the roadside unit The perpetrator was found in the quadruple, confirming their true identity as originating from the roadside unit. This completes the tracking of malicious nodes.
9. The vehicle-roadside unit mutual trust authentication and key negotiation method according to claim 1, characterized in that, The communication entity adds the fake identity identifier of the fake message sender to the communication entity's incremental fake identity identifier revocation list, thereby completing the revocation of the fake message sender, specifically including: Upon receiving a false or malicious message, the communication entity generates a warning message. The warning message Including false identities of malicious communication entities ; The communication entity calculates the key of the Trusted Center (TA). When the communication entity is the roadside unit At that time, the Extract the triplet from the first memory. ; through calculation , Determine TA's key When the communication entity is the vehicle At that time, the vehicle Retrieve triplets from the second memory Through calculation , Determine TA's key ; Based on the key of the Trusted Center (TA) The communication entity responds to the warning message Encryption is performed, and an encrypted warning message is generated. and the encrypted warning message Send to a trusted center (TA); wherein the encrypted warning message for ; The trusted center TA receives the encrypted warning message. Then, the encrypted warning message Broadcast to the communication entity; The communication entity receives a broadcast message from the Trusted Center (TA). Then, based on the key The encrypted warning message Decryption was performed, and the original warning message was obtained. The original warning message for ; The communication entity based on the original warning message To determine the pseudo-identity of the communication entity that sent the false or malicious message. ; When the message is received The roadside unit Check the sender's pseudo-identity. Is it in its incremental pseudo-identity revocation list (IPRL)? If in, the roadside unit Confirm the vehicle For malicious vehicles that have had their licenses revoked, the roadside unit is terminated. With the vehicle Identity mutual trust authentication and session key negotiation; When the message is received The vehicle The detection Is it in its incremental pseudo-identity revocation list (IPRL)? If so, the vehicle Confirm the roadside unit For malicious roadside units that have been revoked, the vehicle will be terminated. With the roadside unit The identity mutual trust authentication and session key negotiation are used to complete the revocation of the malicious node; the malicious node includes the vehicle. or the roadside unit .
Citation Information
Patent Citations
Authentication key negotiation method based on physical security and suitable for Internet of Vehicles environment
CN116707788A
Physical unclonable function based mutual authentication and key exchange
US20230032099A1