V2R mutual trust authentication and session key negotiation method

Through the lightweight authentication method of vehicles and roadside units, non-clone functions and hashing operations, the problem of identity counterfeiting and information security in the Internet of Vehicles is solved, efficient and secure identity authentication and session key negotiation is achieved, and the dependence on trusted centers is reduced. It is suitable for resource-constrained devices and is suitable for Internet of Vehicles environments.

CN120378876AActive Publication Date: 2025-07-25CHANGZHOU INST OF TECH

Patent Information

Application Number
CN202510499912.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-25
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

In the Internet of Vehicles, the exchange of information between vehicles and vehicles, and between vehicles and roads is easily subject to security threats such as identity counterfeiting attacks, information interception, information tampering and privacy leakage. The existing identity authentication and key negotiation solutions require the direct participation of a trusted center, resulting in a large number of message exchanges, a long number of bits, and a complex calculation, which cannot meet the communication needs of the Internet of Vehicles environment with rapid changes in high-speed movement and topological structure.

Method used

The lightweight authentication method of vehicles and roadside units is adopted, and the registration of vehicles and roadside units, identity mutual trust authentication and session key negotiation are realized through non-clone functions and hashing operations, reducing the number and length of authentication messages, reducing calculation overhead, and tracking and revoking after the malicious communication entity is identified.

Benefits of technology

Two-way identity authentication between the vehicle and the roadside unit is realized, which reduces the computing burden on the trusted center, reduces the number of authentication message exchanges and delays, improves authentication efficiency and security, prevents malicious communication entities from committing evil, and reduces the risk of single point of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378876A_ABST
    Figure CN120378876A_ABST
Patent Text Reader

Abstract

The invention discloses a V2R mutual trust authentication and session key negotiation method, and relates to the field of secure communication, and the method comprises the steps: selecting identities, passwords and keys of a vehicle and a road side unit, completing vehicle registration based on the identity, the password, a first challenge and a first response of the selected vehicle, and completing vehicle registration based on the identity and the key of the selected road side unit. Completing the registration of the road side unit, and obtaining and storing the registration information of the vehicle and the road side unit; and vehicle access identity verification is completed based on the identity label and the password of the vehicle and the vehicle registration information, and identity mutual trust authentication and session key negotiation between the vehicle and the road side unit are completed through authentication message interaction between the vehicle and the road side unit and verification of to-be-verified parameters in the authentication message. The trusted center is only used for registration of the vehicle and the road side unit and tracking and revoking of malicious communication entities, the number and length of authentication message forwarding are reduced, and authentication safety and efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of secure communications, and in particular to a V2R mutual trust authentication and session key negotiation method. Background Art

[0002] In the Internet of Vehicles, vehicles and roads (V2R) exchange data and share information to update information such as road conditions, traffic congestion, vehicle location, and lane capacity, so as to improve traffic conditions and traffic efficiency, avoid vehicle collisions and road traffic accidents, and ensure traffic safety. However, the information exchange between vehicles and roads is transmitted through wireless public channels, which is vulnerable to serious security threats such as identity spoofing attacks, information interception, information tampering, false message injection, and privacy and sensitive information leakage. At present, identity authentication and key negotiation solutions are mostly used to solve this problem. From the perspective of technical means of implementation, the current solution requires the trusted authority (TA) to directly participate in the authentication, and mutual trust authentication is achieved through mutual information transmission between vehicles, TAs, and roadside units (RSUs). However, due to the large number of messages exchanged in this authentication method and the long number of bits to be exchanged, it takes a longer time to complete the mutual trust authentication of identity, which is not conducive to the timely communication needs in the Internet of Vehicles scenario. What is more serious is that in high-speed and high-density vehicle scenarios, TA is very heavily burdened and easily causes "single point failures", which seriously reduces the communication speed and is not conducive to the vehicle network environment where vehicles move at high speed and the topology changes rapidly. In addition, the current solutions are computationally complex and have high computational overhead. How to use lightweight operations, not let TA directly participate in V2R identity mutual trust authentication, but only use it for vehicle and RUS registration, and track and revoke the identity of malicious communication entities, reduce computational overhead, reduce the number and length of message forwarding, reduce communication overhead, and improve authentication efficiency has become a technical problem that needs to be solved in this field. Summary of the invention

[0003] The purpose of this application is to provide a V2R mutual trust authentication and session key negotiation method, so that TA is only used for vehicle and RUS registration, and to track and revoke the identity of malicious communication entities, reduce computing overhead, reduce the number and length of authentication message forwarding, reduce communication overhead, and improve the efficiency of V2R mutual trust authentication and key negotiation.

[0004] To achieve the above objectives, this application provides the following solutions:

[0005] In a first aspect, the present application provides a V2R mutual trust authentication and session key negotiation method, including:

[0006] The vehicle selects its own identity identifier and password, generates a binary string as a challenge, and completes vehicle registration based on the selected vehicle identity identifier and password, the challenge and response of the unclonable function, obtaining and storing vehicle registration information; the process of vehicle registration is realized through information interaction between the vehicle and the trusted center;

[0007] The roadside unit selects its own identity identifier and key, and completes roadside unit registration based on the identity identifier and key, obtaining and storing roadside unit registration information; the process of roadside unit registration is realized through information interaction between the roadside unit and the trusted center;

[0008] Based on the vehicle's identity identifier and password, and vehicle registration information, vehicle access authentication is completed, and through the authentication message interaction between the vehicle and the roadside unit, and the verification of the parameters to be verified in the authentication message, mutual identity trust authentication and session key negotiation between the vehicle and the roadside unit are completed; after the mutual trust authentication between the vehicle and the roadside unit is passed, the trusted center tracks and revokes the true identities of malicious communication entities.

[0009] Optionally, the vehicle selects its own identity identifier and password, generates a binary string as a challenge, and completes vehicle registration based on the selected vehicle identity identifier and password, the challenge and response of the unclonable function, obtaining and storing vehicle registration information, including:

[0010] The vehicle selects its own identity identifier ID i and key PW i , and generates a first binary string

[0011] The first binary string is used as the first challenge of the unclonable function to obtain a first response through the unclonable function embedded in the vehicle

[0012] Based on the vehicle's identity identifier ID i , password PW i , the first challenge and the first response complete the registration request reqv; and send the registration request reqv to the trusted center;

[0013] After receiving the registration request reqv, the trusted center checks whether the vehicle's identity identifier ID i exists in its database;

[0014] If it exists, it indicates that the identity identifier ID i has been used by other vehicles, and the vehicle is notified to re-select the identity identifier;

[0015] If not, the trusted center generates a registration response res1 for the vehicle based on the first challenge the identity identifier ID of the vehicle i and the password PW i and the first response and sends the registration response res1 to the vehicle;

[0016] The vehicle generates vehicle registration information based on the registration response res1; the vehicle registration information includes: the association parameter X between the vehicle and the trusted center i the vehicle's authentication parameter Ver i the vehicle's obfuscated identity identifier MID i the association parameter Rel between the trusted center and the roadside unit i and the first challenge

[0017] Optionally, the roadside unit selects its own identity identifier and key, and completes the registration of the roadside unit based on the identity identifier and key, obtains and stores the roadside unit registration information, including:

[0018] The roadside unit selects its own identity identifier ID j and the key K j , stores the key K j in the non-tamperable module TPM of the roadside unit, and generates a registration request reqr for the roadside unit based on the selected identity identifier ID j and the key K j and sends the registration request reqr to the trusted center;

[0019] After receiving the registration request reqr, the trusted center checks whether there is an identity identifier ID of the roadside unit in the database of the trusted center j ;

[0020] If it exists, it indicates that the selected identity identifier ID j has been used by other roadside units, and the trusted center notifies the roadside unit to re-select the identity identifier;

[0021] If not, the trusted center stores the identity identifier ID of the roadside unit j and the key K j in its database; subsequently, the trusted center generates a random number RN ta , and constructs a registration response res2 for the roadside unit based on the random number RN ta ; res2 = <RN ta , W>, where W is an intermediate temporary variable; and sends the registration response res2 to the roadside unit;

[0022] After the roadside unit receives the registration response res2, it stores the registration information (ID j , Y, W), where is also an intermediate temporary variable.

[0023] Optionally, based on the vehicle's identity identifier and password, and the vehicle registration information, complete the vehicle access authentication, and through the authentication message interaction between the vehicle and the roadside unit, as well as the verification of the parameters to be verified in the authentication message, complete the identity mutual trust authentication and session key negotiation between the vehicle and the roadside unit, including:

[0024] Input the true identity identifier ID of the vehicle i and password PW i , and retrieve the vehicle registration information from the vehicle's memory, and determine the pseudo-identity identifier PID of the vehicle based on the retrieved vehicle registration information i , the temporary parameter W related to the key K between the roadside unit and the trusted center ta , and the temporary parameter V related to the key K of the roadside unit k ; j j i ;

[0025] Based on the association parameter X between the vehicle and the trusted center i , and the temporary parameter V related to the key K of the roadside unit j determine the verification parameter Ver of the vehicle j ; i ;

[0026] Judge whether the verification parameter Ver of the vehicle i is equal to the vehicle's identity verification parameter in the vehicle registration information, that is get the first judgment result;?= means whether it is equal to;

[0027] When the first judgment result is yes, generate a second binary string and use the second binary string as the challenge of the unclonable function to obtain the second response

[0028] Generate the first timestamp t1, and based on the pseudo-identity identifier PID of the vehicle i , the identity identifier ID of the roadside unit j , the temporary parameter W related to the key K of the trusted center ta , the second binary string k , the second response and the association parameter Rel between the trusted center and the roadside unit i ​Generate the first authentication message Msg1; the first authentication message Msg1 includes: the obfuscated identity identifier MID of the vehicle i , the first temporary parameter A1 in the identity authentication and key negotiation process, the first authentication parameter A2 in the identity authentication and key negotiation process, and the first timestamp t1;

[0029] After receiving the first authentication message Msg1, the roadside unit determines the validity of the first timestamp t1 in the first authentication message Msg1;

[0030] When the first timestamp t1 is valid, the roadside unit uses the key K j to decrypt the obfuscated identity identifier MID of the vehicle i and determines the second authentication parameter in the identity authentication and key negotiation process based on the decrypted parameters where h() represents a hash function;

[0031] Determine whether the first authentication parameter A2 in the identity mutual trust authentication and key negotiation process is equal to the second authentication parameter in the identity authentication and key negotiation process to obtain a second judgment result;

[0032] When the second judgment result is yes, the roadside unit completes the identity authentication of the vehicle;

[0033] The roadside unit is based on the pseudo-identity identifier PID of the vehicle i , the password PW of the vehicle i , the first binary string the first response the second binary string and the second response to determine the new obfuscated identity identifier of the vehicle and the second temporary parameter B1 in the authentication and key negotiation process between the vehicle and the roadside unit;

[0034] The roadside unit generates a second timestamp t2 and is based on the pseudo-identity identifier PID of the vehicle i , the temporary parameter W related to the trusted center key K ta , the temporary parameter V related to the key K of the roadside unit k , the key K of the roadside unit j , the temporary parameter V j , the first binary string the second binary string the second timestamp t2 and the new obfuscated identity identifier of the vehicle Generate a second authentication message Msg2 and send the second authentication message Msg2 to the vehicle; the second authentication message Msg2 includes: a second temporary parameter B1 in the authentication and key negotiation process between the vehicle and the roadside unit, a third authentication parameter B2 in the authentication and key negotiation process between the vehicle and the roadside unit, and a second timestamp t2; the roadside unit determines the session key SK ij , where

[0035] After receiving the second authentication message Msg2, the vehicle determines the validity of the second timestamp t2; when the second timestamp t2 is valid, the vehicle is based on its pseudo-identity PID i , the temporary parameter W related to the key K with the trusted center ta , the temporary parameter V related to the key K with the roadside unit k , the key K with the roadside unit j , the temporary parameter V j , the first binary string and the second binary string to determine the fourth authentication parameter in the authentication and key negotiation process between the vehicle and the roadside unit where

[0036] Judge whether the third authentication parameter B2 in the mutual trust authentication and key negotiation process between the vehicle and the roadside unit is equal to the fourth authentication parameter in the mutual trust authentication and key negotiation process between the vehicle and the roadside unit to obtain a third judgment result;

[0037] When the third judgment result is yes, the vehicle completes the authentication of the roadside unit's identity; the vehicle determines its session key SK ij , where and updates the obfuscated identity MID stored in its memory with the vehicle's new obfuscated identity i .

[0038] Optionally, after the mutual trust authentication between the vehicle and the roadside unit, the trusted center can track and revoke the true identities of malicious communication entities, including:

[0039] The roadside unit receives the first authentication message Msg1 sent by the vehicle and is based on the vehicle's pseudo-identity PID i , the identity ID of the roadside unit j , the temporary parameter W related to the key K between the roadside unit and the trusted center ta , the temporary parameter W k , the second binary string the second response and the first timestamp t1 to determine the first hash value ​

[0040] Judge the first hash value Whether the first authentication parameter A2 in the identity mutual trust authentication and session key negotiation process between the vehicle and the roadside unit is equal, and obtain the fourth judgment result;

[0041] When the fourth judgment result is no, the identity of the vehicle cannot pass the authentication, and the received first authentication message Msg1 is discarded;

[0042] When the fourth judgment result is yes, the identity of the vehicle is authenticated by the roadside unit, and the roadside unit determines and records the confused identity identifier MID of the vehicle according to the received first authentication message Msg1 i ;

[0043] When it is detected that the vehicle sends a false / malicious message, the roadside unit adds the confused identity identifier MID of the vehicle i to the incremental confused identity identifier revocation list IMRL of the roadside unit, and based on its own identity identifier ID j and the key K j and the confused identity identifier MID of the vehicle i Calculate the second hash value V ta , where V ta =h(MID i ||ID j ||K j ), and based on the second hash value V ta and the confused identity identifier MID of the vehicle i Generate a revocation message Revo, where Revo = <MID i ,V ta >, and send the revocation message Revo to the trusted center;

[0044] When receiving the revocation message Revo, the trusted center extracts the identity identifier ID of the roadside unit from its database j and the key K j , and determines the third hash value based on the revocation message where, And judge whether the third hash value is equal to the second hash value V ta , and obtain the fifth judgment result;

[0045] When the fifth judgment result is yes, the trusted center uses its key K ta , decrypt the confused identity identifier MID of the vehicle in the revocation message Revo i , to obtain the pseudo-identity identifier PID of the vehicle i , and based on the pseudo-identity identifier PID of the vehicle i Query the true identity identifier ID of the vehicle iIs there a binary tuple data (ID i , PID i )? The binary tuple data includes the true identity identifier ID of the vehicle i and the pseudo-identity identifier PID of the vehicle i ;

[0046] When the pseudo-identity identifier PID of the vehicle is detected i and there is a binary tuple data (ID i , PID i ), the trusted center determines the true identity ID of the vehicle sending the false / malicious message i , completes the tracking of the vehicle sending the false / malicious message, and generates a broadcast message CMID i ; where represents performing an encryption operation on * using the key K of the trusted center ta ;

[0047] The trusted center broadcasts the broadcast message CMID i to all other roadside units except the roadside unit that reports the revocation message;

[0048] After receiving the broadcast message CMID i , the roadside unit extracts its key K from its non-tamperable module TPM j , extracts (ID j , Y, W) from its memory, and then according to K temp = h(ID j ||RN ta ), calculates and obtains the key K of the trusted center ta , and uses K ta to decrypt the received broadcast message CMID i , obtains the obfuscated identity identifier MID of the vehicle sending the false / malicious message i , and adds the obfuscated identity identifier MID of the decrypted vehicle i to its incremental obfuscated identity revocation list IMRL;

[0049] When the vehicle sending the false message sends a first authentication message Msg1 to other roadside units, after the roadside unit receives Msg1, it checks whether the obfuscated identity identifier MID of the vehicle i is in its incremental obfuscated identity revocation list IMRL; if it is not in the incremental obfuscated identity revocation list IMRL, it indicates that the vehicle is a normal vehicle; if it is in the incremental obfuscated identity revocation list IMRL, it indicates that the vehicle is a revoked vehicle, and the identity authentication is terminated.

[0050] Optionally, before selecting the identity identifier and password of the vehicle, and completing vehicle registration based on the selected identity identifier and password of the vehicle to obtain and store vehicle registration information, the V2R mutual trust authentication and session key negotiation method further includes:

[0051] Complete the presetting of the trusted center key, the presetting of the roadside unit key, and complete the embedding of the unclonable device in the vehicle; the unclonable function is implanted in the unclonable device;

[0052] Select a one-way Hash function and a symmetric encryption and decryption standard.

[0053] Optionally, select SHA-256 as the one-way Hash function.

[0054] Optionally, select AES-128 block encryption as the symmetric encryption and decryption standard.

[0055] According to the specific embodiments provided in this application, this application has the following technical effects:

[0056] This application provides a V2R mutual trust authentication and session key negotiation method. Based on the identity identifier and password of the vehicle and the vehicle registration information, vehicle access authentication is completed. Through the authentication message interaction between the vehicle and the roadside unit and the verification of the parameters to be verified in the authentication message, two-way authentication between the vehicle and the roadside unit is realized, which can ensure the legality of the identities of both parties in the information exchange and prevent attackers from impersonating communication entities to send false messages. During the two-way authentication process between the vehicle and the roadside unit, the session key negotiation between the vehicle and the roadside unit is completed, which greatly reduces the burden on the TA caused by the identity authentication between dense communication entities, and reduces the number of authentication message exchanges and the transmission delay. Moreover, this method can also realize the tracking and revocation of the identities of malicious communication entities and prevent the malicious behavior of communication entities with legal identities. This application only uses the TA for the registration of vehicles and RUSs and the tracking and revocation of the identities of malicious communication entities to prevent the TA from having a single point of failure in a dense vehicle scenario and improve the security and efficiency of authentication. Description of the Drawings

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0058] Figure 1 It is a schematic flowchart of a V2R mutual trust authentication and session key negotiation method provided by an embodiment of the present application;

[0059] Figure 2Schematic diagram of the vehicle registration process provided by an embodiment of the present application;

[0060] Figure 3 Schematic diagram of the registration process of the roadside unit provided by an embodiment of the present application. Detailed implementation manners

[0061] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0062] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0063] In an exemplary embodiment, the present application provides a V2R mutual trust authentication and session key negotiation method, which is executed by a computer device. Specifically, it can be executed independently by a computer device such as a terminal or a server, or jointly executed by a terminal and a server. In the embodiments of the present application, this method is described by taking the example that it is applied to a server. The method includes:

[0064] Step 100: The vehicle selects its own identity identifier and password, and generates a binary string as a challenge, and completes vehicle registration based on the selected vehicle identity identifier and password, the challenge and response of the unclonable function, and obtains and stores vehicle registration information. The process of vehicle registration is achieved through information interaction between the vehicle and the trusted center.

[0065] Step 101: The roadside unit selects its own identity identifier and key, and completes roadside unit registration based on the identity identifier and key, and obtains and stores roadside unit registration information. The registration process of the roadside unit is achieved through information interaction between the roadside unit and the trusted center.

[0066] Step 102: Based on the vehicle's identity identifier and password, and vehicle registration information, complete vehicle access authentication, and through the interaction of authentication messages between the vehicle and the roadside unit, and the verification of the parameters to be verified in the authentication messages, complete the mutual trust authentication and session key negotiation between the vehicle and the roadside unit. After the mutual trust authentication between the vehicle and the roadside unit is passed, the trusted center tracks and revokes the true identities of malicious communication entities.

[0067] Based on the above-provided Steps 100 - 102, this application can use the TA only for the registration of vehicles and roadside units, as well as for tracking and revoking the identities of malicious communication entities, reducing the quantity and length of authentication message transmissions, and improving the security and efficiency of authentication.

[0068] In another exemplary embodiment of this application, the vehicle Vehicle i sends a registration request message to the TA through a secure channel, and the TA sends the registration response to the vehicle Vehicle through the secure channel i , and the registration process of the vehicle Vehicle i is as follows Figure 2 shown, including:

[0069] Step1: The vehicle Vehicle i selects its own true identity identifier ID i and password PW i , generates a first binary string as a challenge, and obtains a first response i through the physically unclonable function PUF i embedded in the vehicle Vehicle Then, the vehicle Vehicle i sends a registration request

[0070] to the TA through a secure channel i Step2: After receiving the registration request reqv, the TA first checks whether the true identity identifier ID i of the vehicle Vehicle exists in the TA's database. If it exists, it notifies the Vehicle i to re-select another identity identifier. Otherwise, the TA calculates stores the binary tuple (ID i , PID i ) in the TA's database, and then sends a first registration response res1: <MID i , W i , Rel k , Rel i > to the vehicle Vehicle through the secure channel.

[0071] Step3: After receiving the first registration response res1, the vehicle Vehicle i calculates Then it stores its system parameters i.e., the registration information of the vehicle Vehicle i in its memory. Among them, Xi Represents the association parameters between the vehicle and the trusted center, Ver i Represents the vehicle's authentication parameters, MID i Represents the obfuscated identity identifier of the vehicle, Rel i Represents the association parameters between the trusted center and the roadside unit. Among them, Represents the exclusive OR operation.

[0072] In another exemplary embodiment of the present application, the roadside unit RSU only selects its own identity identifier and key. Based on this, in this embodiment, the roadside unit RSU j The registration process is as follows Figure 3 shown, including:

[0073] Step1: The roadside unit RSU j Selects its own identity identifier ID j and key K j , stores the key K j in its tamper-proof module TPM, and then sends the roadside unit registration request reqr: <ID j ,K j > to the trusted center through a secure channel.

[0074] Step2: After receiving the registration request reqr, the trusted center first checks whether the true identity identifier ID j of the roadside unit RSU j exists in its database. If it exists, it notifies the RSU j to re-select another identity identifier. Otherwise, the RSU j stores (ID j ,K j ). Then it generates a random number RN ta , calculates the intermediate temporary variable K temp =h(ID j ||RN ta ) and Then constructs the second registration response res2: <RN ta ,W>, and sends the second registration response res2 to the roadside unit RSU j through a secure channel.

[0075] Step3: After receiving the second registration response res2, the roadside unit RSU j calculates Stores the roadside unit registration information (ID j ,Y,W) in its memory.

[0076] In another exemplary embodiment of the present application, during the login, authentication, and key negotiation process, the vehicle completes the authentication of its identity when accessing the vehicle by the user entering its identity identifier and password. If the authentication fails, the vehicle cannot log in to the VANETs network. Only by passing the authentication can the vehicle log in to the VANETs network, and then through the interaction of authentication messages with the roadside unit and the verification of the parameters to be verified in the authentication message, the mutual authentication and session key negotiation between the vehicle and the roadside unit are completed. Based on this, the login, authentication, and key negotiation process can be: based on the identity identifier and password of the vehicle, the vehicle registration information, and the identity identifier and key of the roadside unit, the roadside unit registration information, through the interaction of authentication messages between the vehicle that has completed the access identity authentication and the roadside unit, and the verification of the parameters to be verified in the authentication message, the mutual trust authentication and session key negotiation between the vehicle and the roadside unit are completed. As Figure 1 shown, the process of completing vehicle login, mutual trust authentication, and session key negotiation between the vehicle and the roadside unit includes:

[0077] Step1: The user enters the true identity identifier ID i of the vehicle Vehicle i and password PW i , and extracts the parameters X i , Rel i , Ver i and MID i from its memory, and then calculates the pseudo-identity identifier i of the vehicle Vehicle temporary parameters related to the trusted center key and temporary parameters related to the key of the roadside unit

[0078] Step2: The vehicle Vehicle i calculates the verification parameter and then checks Ver i * ? = Ver i . If the two are not equal, it indicates that the login authentication of the vehicle Vehicle i fails, and the system terminates the current mutual trust authentication and session key negotiation process. Otherwise, the vehicle Vehicle i generates a second binary string as the challenge input of the physically unclonable function PUF i and obtains its response (i.e., the second response) i through the physically unclonable function PUF

[0079] Step3: The vehicle Vehicle i generates a first timestamp t1, and then calculates the temporary parameters in the identity mutual trust authentication and session key negotiation process and the first authentication parameter in the identity mutual trust authentication and session key negotiation process Then it sends a first authentication message Msg1 to the roadside unit RSU j : <MID i , A1, A2, t1>. h() is a hash function

[0080] Step4: After receiving the first authentication message Msg1, the roadside unit RSU j first checks the validity of the first timestamp t1. If |t1 - t| > ε (i.e., the first timestamp is invalid), where t is the system time when Msg1 is received, to prevent replay attacks, the current identity mutual trust authentication and session key negotiation process is terminated. Otherwise, the roadside unit RSU j considers the first timestamp t1 valid, and uses its key K j to decrypt the confused identity identifier MID of the vehicle in the received Msg1 i to obtain and calculates

[0081] Step5: The roadside unit RSU j calculates and the second authentication parameter in the identity mutual trust authentication and session key negotiation process checks If they are not equal, it indicates that the RSU j has failed in authenticating the identity of the vehicle Vehicle i , and the system terminates the current identity mutual trust authentication and session key negotiation process. Otherwise, the identity of Vehicle i is authenticated by the roadside unit RSU j .

[0082] Step6: The roadside unit RSU j calculates the new confused identity identifier of the vehicle Vehicle i and the second temporary parameter in the identity mutual trust authentication and session key negotiation process between the vehicle and the roadside unit where means encrypting * with the key K of the trusted center ta j

[0083] Step7: The roadside unit RSU j ​Generate a second timestamp t2, and then calculate the second authentication parameter in the mutual trust authentication and session key negotiation process between the vehicle and the roadside unit and the session key Then send the second authentication message Msg2: <B1, B2, t2> to the vehicle Vehicle i Send the second authentication message Msg2: <B1, B2, t2>.

[0084] Step8: After receiving the second authentication message Msg2, the vehicle Vehicle i first checks the legitimacy of the second timestamp t2. If |t2 - t| > ε (i.e., the second timestamp is invalid), where t is the system time when Msg2 is received, to prevent replay attacks, the current authentication and session key negotiation process is terminated. Otherwise (i.e., the second timestamp is valid), the vehicle Vehicle i calculates and the second authentication parameter in the mutual trust authentication and session key negotiation process between the vehicle and the roadside unit Then checks If the two are not equal, it indicates that the vehicle Vehicle i has failed to authenticate the identity of the roadside unit RSU j , and the system terminates the current mutual trust authentication and session key negotiation process. Otherwise, the identity of the roadside unit RSU j is authenticated by the vehicle Vehicle i , and then the vehicle Vehicle i calculates the session key and uses to update its system parameter MID i .

[0085] In another embodiment of the present application, through the information interaction between the vehicle that has completed the identity access verification and the roadside unit, the process of completing the mutual trust authentication between the vehicle and the roadside unit can be described as follows: Based on the obfuscated identity identifier of the vehicle, the identity identifier and key of the roadside unit, the pseudo-identity identifier of the vehicle, the identity identifier and password of the vehicle, the first binary string, and the second response, through the information interaction between the roadside unit and the trusted center, the identity tracking and revocation of malicious vehicles are completed. Based on this, the process of tracking and revoking malicious vehicle nodes can be described as:

[0086] Step1: The vehicle Vehicle i sends the first authentication message Msg1: <MID j , A1, A2, t1> to the roadside unit RSU i , and the roadside unit RSU j completes the authentication of the vehicle Vehicle by verifying iAuthentication. If they are equal, the roadside unit RSU j completes the authentication of the vehicle Vehicle i and records the obfuscated identity identifier MID i of the vehicle Vehicle i .

[0087] Step2: Once it is detected that the vehicle Vehicle i sends a false / malicious message, the roadside unit RSU j adds the MID i to its incremental obfuscated identity revocation list IMRL and calculates the second hash value V ta = h(MID i ||ID j ||K j ), and sends the revocation message Revo: <MID i ,V ta > to the TA

[0088] Step3: When receiving the revocation message Revo, the TA calculates the third hash value Check If they are not equal, it indicates that the revocation message is not reported by the roadside unit RSU j . If they are equal, the TA decrypts the obfuscated identity identifier MID of the vehicle Vehicle i to obtain the pseudo identity identifier PID i of the vehicle Vehicle i , and then queries the tuple data (ID i , PID i ) in its database according to the pseudo identity identifier PID i of the vehicle Vehicle i . If found, the trusted center determines the true identity ID i of the vehicle that sends the false / malicious message i , and completes the tracking of the vehicle that sends the false / malicious message. Among them, represents decrypting * with the key K ta .

[0089] Step4: The TA broadcasts the message CMID i to all other roadside units except the roadside unit RSU j . Among them, Among them, represents encrypting the MID ta with the key K i of the TA

[0090] Step5: Receive the broadcast message CMID i After that, the roadside unit extracts its key K from its TPM j , extracts (ID j , Y, W) from its memory, and then calculates K temp = h(ID j ||RN ta ), and Using the calculated key K of TA ta , perform the decryption operation, indicating decrypting CMID ta with the key K i . Then, add the obfuscated identity identifier MID i of the vehicle Vehicle i obtained by decryption to the incremental obfuscated identity revocation list IMRL of the roadside unit that performs the decryption operation.

[0091] Step6: When a malicious vehicle Vehicle i sends a first authentication message Msg1: <MID j , A1, A2, t1> to any roadside unit RSU i , the roadside unit RSU j first checks whether the obfuscated identity identifier MID i of the vehicle Vehicle i is in its incremental obfuscated identity revocation list IMRL. If the obfuscated identity identifier MID i of the vehicle Vehicle i is not in its incremental obfuscated identity revocation list IMRL, it indicates that the authentication is initiated by a normal vehicle. If the obfuscated identity identifier MID i of the vehicle Vehicle i is in its incremental obfuscated identity revocation list IMRL, it indicates that the vehicle Vehicle i has been revoked, terminates its identity authentication, and does not receive any messages sent by the revoked vehicle Vehicle i . i

[0092] In another embodiment of the present application, the above method provided by the present application can be divided into four stages, namely system initialization, vehicle registration (step 100), roadside unit registration (step 101), and mutual trust authentication and session key negotiation stage between the vehicle and the RSU (step 102). Based on this, in this embodiment, the system initialization stage can be completed by the system administrator, including:​

[0093] Step1: The system administrator completes the preset of the trusted center key K ta and the preset of the roadside unit RSU j key K j and completes the embedding of the physically unclonable function PUF i in the vehicle Vehicle i .

[0094] Step2: The system administrator selects a one-way Hash function and a symmetric encryption and decryption standard. Among them, SHA-256 is selected as the one-way Hash function, and AES-128 block encryption is selected as the symmetric encryption and decryption standard.

[0095] In summary, this application uses a physically unclonable function, lightweight one-way hashing operation Hash, and bitwise exclusive OR operation XOR to implement two-way identity authentication and session key negotiation between vehicles and roadside units in the vehicle networking environment, which is mainly reflected in the following aspects:

[0096] 1) It realizes two-way identity authentication between vehicles and roadside units, can ensure the legitimacy of the identities of both parties in information exchange, and prevent attackers from impersonating communication entities to send false messages.

[0097] 2) It realizes the negotiation of session keys between vehicles and roadside units. Sensitive messages are encrypted and transmitted using session keys, and the receiving party decrypts them using session keys to ensure the confidentiality of the transmitted messages.

[0098] 3) It realizes the anonymity of communication entities. During the message transmission process, both the sender and the receiver exchange information anonymously, protecting the privacy of users and preventing the tracking of communication entities in the vehicle networking.

[0099] 4) It prevents cloning and physical attacks. This method uses a physically unclonable function, which has the advantages of lightweight, low power consumption, high throughput, non-replicable, difficult for adversaries to impersonate and predict, and does not require additional storage space to store keys or random numbers.

[0100] 5) It is suitable for identity mutual trust authentication and session key negotiation of resource-constrained devices. This method uses lightweight hash operations, XOR (exclusive OR) operations, physically unclonable functions, and symmetric encryption and decryption, and the computational overhead is relatively low, which is particularly suitable for identity authentication and session key negotiation between resource-constrained devices.

[0101] 6) This application completes identity authentication and session key negotiation together. It not only has fewer authentication message exchange times, but also has a short length of exchanged messages, which can reduce the transmission delay of messages.

[0102] 7) The authentication of the identities of both communication parties does not require the participation of a trusted third party, which not only greatly reduces the burden on the TA caused by identity authentication and session key negotiation among dense communication entities, but also reduces the probability of "single point of failure" of the TA.

[0103] 8) Realize the tracking and revocation of the identities of malicious vehicles. If the roadside unit receives false or malicious messages, it can send the obfuscated identity identifier of the message sender to the TA. Then the TA decrypts the reported obfuscated identity identifier with its own key to obtain the pseudo-identity identifier of the vehicle, and based on this pseudo-identity identifier, realizes the tracking of the real identity of the vehicle by querying the binary tuple;

[0104] The trusted center TA encrypts the received obfuscated identity identifier of the vehicle with its own key and sends it to all other roadside units except the reporting roadside unit. After receiving the broadcast message of the encrypted obfuscated identity identifier of the vehicle, the roadside unit calculates the key of the trusted center TA by using the key stored in its non-tamperable module TPM and the registration information stored in its memory, and then decrypts the received broadcast message of the encrypted obfuscated identity identifier of the vehicle with this key, so as to obtain the obfuscated identity identifier of the false message sender, and add this obfuscated identity identifier to the incremental obfuscated identity identifier revocation list of the roadside unit, thus completing the revocation of the false message sender.

[0105] In an exemplary embodiment, a computer device is provided. The computer device can be an in-vehicle terminal, a roadside unit terminal or a roadside edge server. The computer device includes a processor, a memory and a communication interface, etc. Among them, the processor and the memory perform data interaction with external devices through the communication interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store V2R mutual trust authentication and session key negotiation data. The communication interface of the computer device is used to exchange information between the processor and external devices, and communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a V2R mutual trust authentication and session key negotiation method.

[0106] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, which when executed by a processor, implements the steps in the above method embodiments.

[0107] In an exemplary embodiment, a computer program product is provided, including a computer program, which when executed by a processor, implements the steps in the above method embodiments.

[0108] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0109] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0110] The databases involved in the various embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the various embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0111] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0112] In this text, specific examples are used to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A V2R mutual trust authentication and session key negotiation method, characterized in that Including: The vehicle selects its own identity identifier and password, generates a binary string as a challenge, and completes vehicle registration based on the selected vehicle identity identifier and password, the challenge and response of the unclonable function, obtaining and storing vehicle registration information; the process of vehicle registration is realized through information interaction between the vehicle and the trusted center; The roadside unit selects its own identity identifier and key, and completes roadside unit registration based on the identity identifier and key, obtaining and storing roadside unit registration information; the process of roadside unit registration is realized through information interaction between the roadside unit and the trusted center; Based on the vehicle's identity identifier and password, and vehicle registration information, vehicle access authentication is completed, and through the interaction of authentication messages between the vehicle and the roadside unit, as well as the verification of the parameters to be verified in the authentication messages, identity mutual trust authentication and session key negotiation between the vehicle and the roadside unit are completed; After the mutual trust authentication between the vehicle and the roadside unit passes, the trusted center tracks and revokes the true identities of malicious communication entities.

2. The V2R mutual trust authentication and session key negotiation method according to claim 1, wherein The vehicle selects its own identity identifier and password, generates a binary string as a challenge, and completes vehicle registration based on the selected vehicle identity identifier and password, the challenge and response of the unclonable function, obtaining and storing vehicle registration information, including: The vehicle selects its own identity identification ID i and the key PW i and generates a first binary string Take the first binary string as the first challenge for the unclonable function Obtain a first response through the unclonable function embedded in the vehicle Vehicle-based identity ID i , password PW i , first challenge and first response Complete the registration request reqv; And send the registration request reqv to the trusted center; After receiving the registration request reqv, the trusted center checks whether the vehicle's identity identifier ID exists in its database i ; If it exists, it indicates that the identity identifier ID i has been used by other vehicles, and the vehicle is notified to re-select the identity identifier; If not, the trusted center generates a registration response res1 for the vehicle based on the first challenge The identity identifier ID of the vehicle i and the password PW i as well as the first response and sends the registration response res1 to the vehicle; The vehicle generates vehicle registration information based on the registration response res1; the vehicle registration information includes: the association parameter X between the vehicle and the trusted center i , the vehicle's authentication parameter Ver i , the vehicle's obfuscated identity identifier MID i , the association parameter Rel between the trusted center and the roadside unit i and the first challenge 3. The V2R mutual trust authentication and session key negotiation method according to claim 2, characterized in that, The roadside unit selects its own identity identifier and key, and completes roadside unit registration based on the identity identifier and key, obtaining and storing roadside unit registration information, including: The roadside unit selects its own identity ID j and the key K j , stores the key K j in the non-tamperable module TPM of the roadside unit, and generates a registration request reqr for the roadside unit based on the selected identity ID j and the key K j , and sends the registration request reqr to the trusted center; After the trusted center receives the registration request reqr, it checks whether the identity identifier ID of the roadside unit exists in the database of the trusted center j ; If it exists, it indicates that the selected identity ID j has been used by other roadside units, and the trusted center notifies the roadside unit to re-select the identity If not, the trusted center will store the identity ID j and the key K j in its database; subsequently, the trusted center generates a random number RN ta , and constructs a registration response res2 for the roadside unit based on the random number RN ta ; res2 = <RN ta , W>, where is an intermediate temporary variable; send the registration response res2 to the roadside unit; After the roadside unit receives the registration response res2, it stores the registration information (ID j , Y, W), where is also an intermediate temporary variable.

4. The V2R mutual trust authentication and session key negotiation method according to claim 3, wherein Based on the vehicle's identity identifier and password, and vehicle registration information, vehicle access authentication is completed, and through the interaction of authentication messages between the vehicle and the roadside unit, as well as the verification of the parameters to be verified in the authentication messages, identity mutual trust authentication and session key negotiation between the vehicle and the roadside unit are completed, including: The true identity identification ID of the input vehicle i and the password PW i , and retrieve the vehicle registration information from the vehicle's memory, and determine the pseudo-identity identification PID of the vehicle based on the retrieved vehicle registration information i and the temporary parameter W related to the road side unit and the trusted center key K ta k and the temporary parameter V related to the key K of the road side unit j j ;​​ Based on the association parameter X between the vehicle and the trusted center i , and the key K with the roadside unit j associated temporary parameter V j Determine the verification parameter Ver of the vehicle i ; Determine the verification parameter Ver of the vehicle i is equal to the vehicle identity verification parameter in the vehicle registration information, that is obtain the first judgment result;?= indicates whether it is equal to; When the first judgment result is yes, generate a second binary string and use the second binary string as a challenge to the uncloneable function to obtain a second response Generate a first timestamp t1 and a pseudo-identity identifier PID based on the vehicle i , Roadside Unit ID j , and the trusted center key K ta Related temporary parameters W k , second binary string Second Response And the association parameter Rel between the trusted center and the roadside unit i Generate a first authentication message Msg1; the first authentication message Msg1 includes: the obfuscated identity identifier MID of the vehicle i , a first temporary parameter A1 in the identity authentication and key negotiation process, a first authentication parameter A2 in the identity authentication and key negotiation process, and a first timestamp t1; After the roadside unit receives the first authentication message Msg1, it determines the validity of the first timestamp t1 in the first authentication message Msg1; When the first timestamp t1 is valid, the roadside unit uses the key K j to decrypt the obfuscated identity identifier MID of the vehicle i and determine the second authentication parameter in the identity authentication and key negotiation process based on the decrypted parameters where h() represents a hash function; Determine whether the first authentication parameter A2 in the identity mutual trust authentication and key negotiation process is equal to the second authentication parameter in the identity authentication and key negotiation process to obtain a second judgment result; When the second judgment result is yes, the roadside unit completes the identity authentication of the vehicle; The roadside unit determines a new obfuscated identity identifier of the vehicle based on the pseudo identity identifier PID of the vehicle i , the password PW of the vehicle i , the first binary string the first response the second binary string and the second response and determines a new obfuscated identity identifier of the vehicle and the second temporary parameter B1 in the authentication and key negotiation process between the vehicle and the roadside unit; The roadside unit generates a second timestamp t2 and, based on the vehicle's pseudo identity identifier PID i , a temporary parameter W related to the trusted center key k , a temporary parameter V related to the roadside unit's key j , a first binary string a second binary string the second timestamp t2 and the vehicle's new obfuscated identity identifier generates a second authentication message Msg2 and sends the second authentication message Msg2 to the vehicle; the second authentication message Msg2 includes: a second temporary parameter B1 in the authentication and key negotiation process between the vehicle and the roadside unit, a third authentication parameter B2 in the mutual identity trust authentication and key negotiation process between the vehicle and the roadside unit, and the second timestamp t2; the roadside unit determines the session key SK ij , where After the vehicle receives the second authentication message Msg2, it determines the validity of the second timestamp t2; when the second timestamp t2 is valid, the vehicle is based on its pseudo identity identifier PID i , and the temporary parameter W related to the trusted center key K ta k , and the temporary parameter V related to the key K of the roadside unit j j , the first binary string , and the second binary string , as well as the second timestamp t2, to determine the fourth authentication parameter in the process of mutual identity trust authentication and session key negotiation between the vehicle and the roadside unit Among them, ​​ Determine whether the third authentication parameter B2 in the identity mutual trust authentication and session key negotiation process between the vehicle and the roadside unit is equal to the fourth authentication parameter in the identity mutual trust authentication and session key negotiation process between the vehicle and the roadside unit to obtain a third judgment result; When the third judgment result is yes, the vehicle completes the authentication of the roadside unit; the vehicle calculates its new obfuscated identity identifier according to and determines its session key SK ij , where and updates the obfuscated identity identifier MID stored in its memory with the new obfuscated identity identifier of the vehicle i .​​ 5. The V2R mutual trust authentication and session key negotiation method according to claim 4, wherein After the mutual trust authentication between the vehicle and the roadside unit passes, the trusted center tracks and revokes the true identities of malicious communication entities, including: The roadside unit receives the first authentication message Msg1 sent by the vehicle and, based on the pseudo identity identifier PID of the vehicle i , the identity identifier ID of the roadside unit j , the temporary parameter W related to the key K between the roadside unit and the trusted center ta , the second binary string k , the second response and the first timestamp t1 to determine the first hash value ​ Determine the first hash value Check whether it is equal to the first authentication parameter A2 in the identity mutual trust authentication and session key negotiation process between the vehicle and the roadside unit, and obtain a fourth judgment result; When the fourth judgment result is no, the identity of the vehicle cannot pass the authentication, and the received first authentication message Msg1 is discarded; When the fourth judgment result is yes, the identity of the vehicle is authenticated by the roadside unit, and the roadside unit determines and records the confused identity identifier MID of the vehicle according to the received first authentication message Msg1 i ; When it is detected that a vehicle sends false / malicious messages, the roadside unit will add the vehicle's obfuscated identity identifier MID i to the roadside unit's incremental obfuscated identity revocation list IMRL, and based on its own identity identifier ID j and the key K j as well as the vehicle's obfuscated identity identifier MID i calculate the second hash value V ta , where V ta = h(MID i ||ID j ||K j ), and based on the second hash value V ta and the vehicle's obfuscated identity identifier MID i generate a revocation message Revo, where Revo = <MID i ,V ta >, and send the revocation message Revo to the trusted center; Upon receiving the revocation message Revo, the trusted center extracts the identity ID of the roadside unit from its database j and the key K j , determines the third hash value based on the revocation message wherein and judges whether the third hash value is equal to the second hash value V ta to obtain the fifth judgment result; When the result of the fifth judgment is yes, the trusted center uses its key K ta , decrypts the obfuscated identity identifier MID of the vehicle in the revocation message Revo i , to obtain the pseudo-identity identifier PID of the vehicle i , and based on the pseudo-identity identifier PID of the vehicle i queries whether the true identity identifier ID of the vehicle i exists in the binary tuple data (ID i , PID i ); the binary tuple data includes the true identity identifier ID of the vehicle i and the pseudo-identity identifier PID of the vehicle i ; When the pseudo-identity identifier PID of the vehicle is detected i and there is a binary tuple data (ID i , PID i ), the trusted center determines the true identity ID of the vehicle sending the false / malicious message i , completes the tracking of the vehicle sending the false / malicious message, and generates a broadcast message CMID i ; where denotes performing an encryption operation on * using the key K of the trusted center ta ; The trusted center will broadcast the message CMID i to all other roadside units except the roadside unit that reports the revocation message; Receive the broadcast message CMID i After that, the roadside unit extracts its key K from its non-tamperable module TPM j , extracts (ID j , Y, W) from its memory, and then according to K temp = h(ID j ||RN ta ), calculate and obtain the key K of the trusted center ta , and use K ta to decrypt the received broadcast message CMID i to obtain the obfuscated identity identifier MID of the false / malicious message sending vehicle i , and add the obfuscated identity identifier MID of the vehicle obtained by decryption i to its incremental obfuscated identity revocation list IMRL; When the vehicle sending false messages sends the first authentication message Msg1 to other roadside units, after receiving Msg1, the roadside unit checks whether the vehicle's obfuscated identity MID i is in its Incremental Obfuscated Identity Revocation List IMRL; if it is not in the Incremental Obfuscated Identity Revocation List IMRL, it indicates that the vehicle is a normal vehicle; if it is in the Incremental Obfuscated Identity Revocation List IMRL, it indicates that the vehicle is a revoked vehicle and terminates the identity authentication.

6. The V2R mutual trust authentication and session key negotiation method according to claim 1, wherein Before selecting the vehicle's identity identifier and password, and completing vehicle registration based on the selected vehicle identity identifier and password, obtaining and storing vehicle registration information, the V2R mutual trust authentication and session key negotiation method further includes: Completing the pre - setting of the trusted center key, the pre - setting of the roadside unit key, and completing the embedding of the unclonable device in the vehicle; the unclonable function is implanted in the unclonable device; Selecting a one - way Hash function and a symmetric encryption and decryption standard.

7. The V2R mutual trust authentication and session key negotiation method according to claim 6, characterized in that Selecting SHA - 256 as the one - way Hash function.

8. The V2R mutual trust authentication and session key negotiation method according to claim 7, wherein Selecting AES - 128 block encryption as the symmetric encryption and decryption standard.

Citation Information

Patent Citations

  • Authentication key negotiation method based on physical security and suitable for Internet of Vehicles environment

    CN116707788A

  • Internet of vehicles efficient batch authentication key negotiation method based on signature

    CN117098128A

  • Lightweight identity authentication and key agreement method for Internet of Vehicles based on PUF (Physical Unclonable Function)

    CN118748592A

  • Security authentication method, system and device for IOV communication based on national cryptographic algorithm

    US20240241938A1

Cited By

  • Power system source network interaction data security encryption verification method, system, device and medium

    CN120710805A