Internet of Vehicles privacy protection method based on CNTR on NTRU lattice
Through NTRU grid cryptography and ring signature technology, the Internet of Vehicles communication is optimized, and the algorithm efficiency and reliability problems under the threat of quantum computing are solved, quantum security protection and equipment compatibility are achieved, and emergency message processing and communication needs of Internet of Vehicles are met.
Patent Information
- Application Number
- CN202510899091.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-01
AI Technical Summary
The existing Internet of Vehicles communications face the problems of low algorithm efficiency, insufficient communication reliability and poor device compatibility under the threat of quantum computing. Traditional encryption technology is difficult to meet the security needs of on-board equipment resource limitations and complex environments.
The NTRU grid cryptography and ring signature technology are adopted, combined with compact Gaussian sampling and mold compression technology, and the algorithm is optimized to adapt to the on-board chip resources, and a dynamic ring mechanism and a linkable label mechanism are built to achieve quantum security protection.
It realizes security protection in a quantum computing environment, with emergency message processing time less than 5 milliseconds, improved communication reliability, reduced ciphertext size, and a decryption success rate of 99.98% in an anti-noise environment. It is adapted to the on-board ECU hardware configuration, and resists side channel attacks.
Smart Images

Figure CN120415733A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information technology security for the Internet of Vehicles, and specifically relates to the application of post-quantum cryptography in vehicle-to-vehicle communication, and particularly to a privacy protection method for the Internet of Vehicles based on a lightweight key encapsulation mechanism of NTRU (Number Theory Research Unit) lattice. Background Art
[0002] With the rapid development of intelligent connected vehicles, data security and privacy protection in vehicle-to-vehicle communication face unprecedented challenges. Currently, the mainstream encryption technologies mainly rely on elliptic curve cryptosystems (such as ECDSA) and traditional public key systems (such as RSA). The vulnerability of these algorithms under quantum computing attacks has become a recognized hidden danger in the industry. The special operation mechanism of quantum computers makes the classical cryptosystem face the risk of being quickly cracked. For example, quantum attacks based on the Shor algorithm can break the existing encryption system within a few hours, which poses a serious threat to the Internet of Vehicles infrastructure that requires long-term security protection.
[0003] The existing technologies expose three key defects in practical applications: First, traditional post-quantum cryptography schemes are difficult to adapt to the resource limitations of in-vehicle devices. A typical in-vehicle microcontroller (MCU) usually has a memory of less than 16KB and a main frequency of the order of 100MHz. However, the key generation process of mainstream quantum-resistant schemes such as NTRU-HRSS requires a computing time of more than 18 milliseconds, significantly exceeding the real-time requirements of vehicle-to-vehicle communication. Second, the high-noise environment of the wireless channel leads to insufficient reliability of existing lattice cryptography schemes. In complex scenarios such as urban canyons, the communication error rate can reach 0.4%, resulting in frequent decryption failures of the schemes based on the ideal lattice assumption, directly affecting vehicle safety decisions. Finally, the existing schemes generally have the problem of low communication efficiency. The excessive ciphertext size exacerbates channel congestion and may cause transmission delays of critical safety information in the vehicle-to-vehicle (V2V) high-frequency communication scenario.
[0004] Although the traditional NTRU (Number Theory Research Unit) algorithm has advantages in anti-quantum characteristics, the complex polynomial inversion operation in its key generation process severely restricts its performance. Taking the NTRU-HRSS scheme as an example, its multiple modular operations and iterative processes not only consume a large amount of computing resources but also result in a high memory occupancy. On the other hand, the schemes based on the learning with errors over rings (RLWE) assumption (such as Kyber) although improve some performance indicators, affect the algorithm efficiency due to the use of non-optimized modulus structures and have inherent defects in side-channel protection. More importantly, none of the existing schemes effectively solve the problem of reliable communication in a noisy environment and lack an adaptive fault-tolerant mechanism designed for the Internet of Vehicles scenario.
[0005] At the engineering implementation level, the compatibility of existing technical solutions with the industry standards of the vehicle networking is insufficient. Currently, the current in-vehicle communication protocols (such as ETSI TS 103 097) and security frameworks (such as Autosar SecOC) have not fully integrated post-quantum cryptographic components, resulting in difficulties in architecture adaptation during actual deployment. In addition, most of the security proofs of traditional solutions are based on idealized assumptions and do not fully consider the unique attack surfaces of in-vehicle systems (such as the physical accessibility of OBU devices), leaving a theoretical gap in verifiable security.
[0006] Currently, the prominent contradiction that the field has long faced is: how to meet the stringent requirements of the vehicle networking environment for algorithm efficiency, communication reliability, and device compatibility while maintaining quantum security. Existing solutions often require trade-offs in different dimensions, and no complete solution that can systematically solve this technical problem has emerged. This situation has severely restricted the security upgrade process of vehicle networking systems, putting the industry in a passive position when dealing with quantum computing threats. Summary of the Invention
[0007] In view of the above problems, the purpose of the present invention is to provide a vehicle networking privacy protection method based on CNTR (a new key encapsulation mechanism) on the NTRU lattice, which uses NTRU lattice cryptography and ring signature technology to achieve quantum security protection for vehicle networking vehicle-to-everything (V2X) communications.
[0008] A vehicle networking privacy protection method based on CNTR on the NTRU lattice provided by the present invention specifically includes the following steps: S1. Initialization settings, where the trusted center configures system parameters; S2. Vehicle registration, where the vehicle registers with the trusted center when leaving the factory and generates the private key of the current vehicle; S3. Road test unit registration, where the public key of the road test unit uses the system public key broadcast by the trusted center, and the private key of the road test unit uses the system private key; S4. Message signcryption, where the signcrypted message is broadcast; S5. Message unsigncryption, where the road test unit uses the system private key to unsigncrypt the signcrypted message sent by the vehicle after obtaining it.
[0009] As a preference of the present invention, step S1 further includes: S1.1. Input to the trusted center at the server layer: security parameter , number of ring members , and then the trusted center determines the system parameters; ring polynomial dimension , modulus , central binomial distribution , Gaussian parameter , and hash function 、 、 ,in Refers to the integer modulus The polynomial ring of ; is a hash function that maps binary data to a ring, It is a hash function that maps polynomials on a ring to binary data. The polynomial in the system private key and The result of the product is mapped into binary data; S1.2. Determine the parameters selected by the trusted center ,in is the independent variable of the polynomial in the ring, is the modulus The integer ring of ; by compact Gaussian sampling in Gaussian distribution Choose a polynomial with small coefficients As the system private key , where the polynomial with small coefficients Must be reversible, otherwise reselect a small coefficient polynomial , use polynomial inversion and polynomial multiplication to calculate the system public key ,in It will The result of the operation and the modulus Take the remainder, Is the system public key ; S1.3, the system public key , hash function Packaged as system public parameters ) and broadcast it to all vehicles, keeping the system private key secret.
[0010] As a preferred embodiment of the present invention, step S2 further includes: S2.1. The vehicle is registered with the trusted center when it leaves the factory. , to obtain a digital certificate, where It is the vehicle's factory ID. is the registration timestamp, As the vehicle public key; S2.2. Generate the current vehicle private key: The vehicle obtains the system public parameters broadcast by the trusted center, and then the vehicle uses compact Gaussian sampling to generate the current vehicle private key in the Gaussian distribution. Select , by calculating Get satisfied of ,Will As the private key of the current vehicle, it is the serial number of the current vehicle, and are two of the vehicle private keys of the current vehicle.
[0011] As a preference of the present invention, step S4 further includes: S4.1. When the vehicle sends a message , first obtain the public keys of 8 surrounding vehicles , , , , , , , to form a dynamic ring , , , , , , , , and obtain the public key of the roadside unit; S4.2. Generate a linkable tag : Package the geographical location of the vehicle sending the message and the time window into a time tag , and package the vehicle private key and the time tag into a linkable tag ; S4.3. Encrypt the message. First, split the message with a length of into multiple groups of 4-bit binary strings such that , and then use the encoding function , , to encode each binary string into a lattice point on an expandable lattice, where , is a scaling factor. Let , be the set of lattice points mapped to ; Then, the vehicle randomly selects a random vector through discrete Gaussian sampling, and randomly selects noise through discrete Gaussian sampling, where . Calculate the blinding vector to blind the random vector , and calculate the signature component , calculate the ciphertext , use the modulo compression technology module to compress the ciphertext , where is the modulo compression function, is the public key when the road test unit is registered; Finally, the dynamic ring , linkable tag , timestamp , blinding vector , signature component , compressed ciphertext are packed into a signcryption message , and the signcryption message is broadcast.
[0012] As a preference of the present invention, step S5 further includes: S5.1. First, the road test unit receives the signcryption message broadcast by the vehicle , uses the decompression technology module to decompress the compressed ciphertext to obtain the ciphertext ; performs a polynomial multiplication operation on the ciphertext with a partial private key of the system private key as the modulus to obtain a random vector , and after excluding the interference term in the ciphertext , obtains the encoded message on the expandable lattice, and decodes the encoded message by solving the closest vector on the expandable lattice to obtain the decoded message , where the decoding function is ; S5.2. After the road test unit receives the signcryption message sent by the vehicle, it verifies the signature. Through the dynamic ring sent by the vehicle, the road test unit obtains 8 vehicle public keys , , , , , , , , and then sequentially verifies the difference between the blinding vector and the signature component for the 8 vehicle public keys , the serial number of the current vehicle. If , is the allowed error, , then the verification is successful and the decoded message is broadcast to other vehicles, otherwise it returns verification failure.
[0013] The beneficial effects of the present invention are as follows: 1. The present invention adopts NTRU lattice cryptography and ring signature technology to achieve quantum security protection for vehicle-to-everything (V2X) communication in the vehicle network. The core features include resistance to quantum attacks. By using the method based on the mathematical problem of "shortest vector problem on lattice", quantum computers cannot quickly crack it. And the algorithm is optimized for in-vehicle chips, making the emergency message processing time < 5 milliseconds.
[0014] 2. The present invention is based on a dynamic ring construction mechanism. By randomly selecting the false identities of neighboring vehicles to form an 8-element confusion ring, even if the attacker intercepts the communication data, it is impossible to determine the real sender's identity through probability analysis. The anonymity strength reaches Pr[recognition success] ≤ 1 / 8, improving the concealment effect by at least 4 times compared with the traditional scheme. Through the PolyEncode method, a fault-tolerant mapping of the message to the polynomial ring is realized. Combining with the NTRU-LWE encryption structure, even in a tunnel scenario with a channel bit error rate as high as 0.35%, the message decryption success rate of 99.98% can still be guaranteed. In addition, the hybrid radix NTT acceleration technology is deeply optimized. According to the instruction set characteristics of in-vehicle chips, a 32 / 16 / 8-bit hierarchical calculation strategy is adopted, reducing the 768-dimensional polynomial multiplication operation period from 12,400 times in the traditional method to 2,150 times. The signcryption operation only takes 4.2 ms on a Cortex-M4@120MHz chip, fully meeting the 5 ms end-to-end delay requirement of the ETSI standard for vehicle network emergency messages.
[0015] 3. In terms of security enhancement, the present invention innovatively realizes the linkable tag mechanism and the quantum-resistant signature structure. By binding the vehicle private key with the spatio-temporal parameters through HMAC-SHA256 to generate the value tag, it not only ensures that the behavior of the same vehicle can be traced within a 5-minute time window, but also can resist the risk of Sybil attacks (the cost of forging identities ≥ 2^128 operations). The modulus compression technology compresses the ciphertext size from 768 coefficients (1152 bytes) to 512 bits. At the same time, the decompression delay is controlled within 0.8 ms by pre-computing the NTT rotation factor, reducing the communication overhead by 62% compared with the traditional ZKP scheme. For side-channel attacks, by adopting a constant-time sampling algorithm, branch prediction vulnerabilities are eliminated in the polynomial multiplication and Gaussian sampling links. After verification by power analysis tests, the risk of key parameter leakage is reduced to below 0.3 nW / bit.
[0016] 4. The CPU occupancy rate of the RSU node of the present invention is only 72% at the peak load of 1200 req / s, and the memory consumption is stable within 8.2 KB, which fully adapts to the hardware configuration of mainstream vehicle ECUs. Through the dynamic mode switching mechanism (SNR threshold set at 20 dB), the system automatically enables the efficient KXOR mode (388 bytes / message) in highway scenarios and switches to the noise-resistant Poly mode (636 bytes / message) in complex urban areas, achieving the optimal balance between communication efficiency and reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] With reference to the following description in conjunction with the drawings, and with a more comprehensive understanding of the present invention, other objects and results of the present invention will become more apparent and easier to understand. In the drawings: Figure 1 is the network model diagram of the present invention; Figure 2 is the system initialization flowchart of the present invention; Figure 3 is the RSU and vehicle registration flowchart of the present invention; Figure 4 is the vehicle signature and encryption sending signature and encryption message flowchart of the present invention; Figure 5 is the RSU decryption and signature verification message flowchart of the present invention; Figure 6 is the UML diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Refer to Figures 1-6 , and the present invention will be further described in detail below in conjunction with the drawings and specific embodiments.
[0019] The embodiment of the present invention provides a vehicle networking privacy protection method based on CNTR on NTRU lattices, which specifically includes the following steps: S1. Initialization settings: S1.1. Input to the trusted center (TA) at the server layer: security parameter , number of ring members , and then the trusted center (TA) determines the system parameters; ring polynomial dimension , modulus , central binomial distribution , Gaussian parameter , and hash functions (constructed based on SHA3-512), (key derivation function), (HMAC-SHA256), where refers to the polynomial ring of the integer modulus ; is a hash function that maps binary data to a ring, is a hash function that maps polynomials on the ring to binary data. The hash function is to map the result after multiplying the polynomials in the system private key and to binary data; S1.2. Determine the ring through the parameters selected by the trusted center, where is the independent variable of the polynomial in the ring, is the modulus of the integer ring; Select a small coefficient polynomial in the Gaussian distribution by means of compact Gaussian sampling as the system private key , where the polynomial with small coefficients must be invertible, otherwise reselect the polynomial with small coefficients, and calculate the system public key using polynomial inversion and polynomial multiplication, where is to take the remainder of the operation result of and the modulus , is the system public key ; S1.3. Package the system public key , the hash function into the system public parameters ) and broadcast them to all vehicles, and secretly store the system private key; S2. Vehicle registration: S2.1. The vehicle registers with the trusted center when it leaves the factory to obtain a digital certificate ( ), where [[ID=�8]]is the vehicle ID when it leaves the factory, is the registration timestamp, as the vehicle public key; S2.2. Generate the current vehicle private key: The vehicle obtains the system public parameters broadcast by the trusted center, and then the vehicle selects in the Gaussian distribution through compact Gaussian sampling, and obtains that satisfies by calculating , and takes as the private key of the current vehicle, is the serial number of the current vehicle, and are two of the vehicle private keys of the current vehicle; S3. Roadside unit (RSU) registration: The public key of the Road Side Unit (RSU) uses the system public key broadcast by the trusted center ; the private key of the Road Side Unit uses the system private key ; S4. Message signcryption: S4.1. When the vehicle sends a message , first obtain the public keys of 8 surrounding vehicles , , , , , , , to form a dynamic ring , , , , , , , , and obtain the public key of the Road Side Unit; S4.2. Generate linkable tags : Pack the geographical location of the vehicle sending the message and the time window into a time tag , and pack the vehicle private key and the time tag into a linkable tag ; S4.3. Encrypt the message. First, split the message with a length of into multiple groups of 4-bit binary strings such that , and then use the encoding function , , to encode each binary string into a lattice point on an expandable lattice ( lattice), where , is the scaling factor. Let , be the set of lattice points mapped to lattice; Then, the vehicle randomly selects a random vector through discrete Gaussian sampling, and randomly selects noise through discrete Gaussian sampling, where . By calculating the blinding vector , the random vector Blinding, calculating the signature component , calculating the ciphertext , using the modular compression technology module to compress the ciphertext , where is the modular compression function, is the public key when the road test unit is registered; Finally, the dynamic ring , linkable tag , timestamp , blinding vector , signature component , compressed ciphertext are packaged into a signcryption message , and the signcryption message is broadcast; S5. Message unsigncryption: S5.1. First, the road test unit receives the signcryption message broadcast by the vehicle , uses the decompression technology module to decompress the compressed ciphertext to obtain the ciphertext ; performs a modular polynomial multiplication operation on the ciphertext and a partial private key of the system private key with the modulus to obtain a random vector , after excluding the interference term in the ciphertext , obtains the encoded message on the expandable lattice ( lattice), and decodes the encoded message by solving the closest vector problem (CVP) on the expandable lattice ( lattice) to obtain the decoded message , where the decoding function is ; S5.2. After the road test unit receives the signcryption message sent by the vehicle, it verifies the signature. Through the dynamic ring sent by the vehicle, the road test unit obtains 8 vehicle public keys , , , , , , , , and then successively verifies the difference between the blinding vector and the signature component for the 8 vehicle public keys , the serial number of the current vehicle. If , is the allowed error, , then the verification is successful and the decoded message Broadcast to other vehicles, otherwise return verification failure.
[0020] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A vehicle networking privacy protection method based on CNTR on NTRU lattice, characterized in that It includes the following steps: S1. Initialization setting, the trusted center configures system parameters; S2. Vehicle registration, when the vehicle leaves the factory, it registers with the trusted center and generates the current vehicle private key; S3. Road test unit registration, the public key of the road test unit uses the system public key broadcast by the trusted center, and the private key of the road test unit uses the system private key; S4. Message signcryption, and broadcast the signcrypted message ; S5. Message decryption and signature verification, after the road test unit obtains the signed and encrypted message sent by the vehicle, it uses the system private key for decryption and signature verification.
2. The privacy protection method for vehicle networking based on CNTR on NTRU lattice according to claim 1, wherein, In step S1, it also includes: S1.
1. Input the following to the trusted center at the server layer: security parameters , the number of ring members , and then the trusted center determines the system parameters; the dimension of the ring polynomial , the modulus , the central binomial distribution , the Gaussian parameter , and the hash functions , , , where refers to the polynomial ring of the integer modulus ; is the hash function that maps binary data to the ring, is the hash function that maps the polynomial on the ring to binary data, and the hash function maps the result of the product of the polynomials and in the system private key to binary data; S1.
2. Determine the ring based on the parameters selected by the trusted center , where is the independent variable of the polynomial in the ring, is the modulus of the integer ring; Select a polynomial with small coefficients in the Gaussian distribution through compact Gaussian sampling as the system private key , where the polynomial with small coefficients must be invertible, otherwise reselect the polynomial with small coefficients, and calculate the system public key using polynomial inversion and polynomial multiplication, where is the result of the operation of modulo the modulus , and is the system public key; S1.
3. Pack the system public key , the hash function into the system public parameters and broadcast them to all vehicles, and secretly store the system private key.
3. A privacy protection method for vehicle networking based on CNTR on NTRU lattice according to claim 1, characterized in that, In step S2, it also includes: S2.
1. The vehicle is registered with the trusted center when leaving the factory , to obtain a digital certificate, where is the vehicle's factory ID, is the registration timestamp, serving as the vehicle's public key; S2.
2. Generate the current vehicle's private key: The vehicle obtains the system public parameters broadcast by the trusted center, and then the vehicle selects in the Gaussian distribution by compact Gaussian sampling , and obtains satisfying through calculation . Take as the current vehicle's private key. is the serial number of the current vehicle. and are two of the current vehicle's private keys.
4. A privacy protection method for vehicle networking based on CNTR on NTRU lattice according to claim 1, characterized in that, In step S4, it also includes: S4.
1. When the vehicle sends a message first, obtain the public keys of 8 surrounding vehicles , , , , , , , to form a dynamic ring , , , , , , , , and obtain the public key of the roadside unit; S4.
2. Generate linkable tags : Package the geographical location of the vehicle that sends the message and the time window into a time tag , and package the vehicle private key and the time tag into a linkable tag ; S4.
3. Encrypt the message. First, split the message with a length of into multiple 4-bit binary strings such that . Then, use the encoding function , , to encode each binary string into lattice points on an expandable lattice, where , is the scaling factor. Let , be the set of lattice points mapped to on the lattice ; Then, the vehicle randomly selects a random vector through discrete Gaussian sampling , and randomly selects noise through discrete Gaussian sampling , where . By calculating the blinding vector , the random vector is blinded, the signature component is calculated, the ciphertext is calculated, and the ciphertext is compressed using the modular compression technology module , where is the modular compression function, and is the public key at the time of registration of the road test unit; Finally, the dynamic ring , linkable tags , timestamps , blinding vectors , signature components , compressed ciphertexts are packed into signcryption messages , and the signcryption messages are broadcasted.
5. The privacy protection method for vehicle networking based on CNTR on NTRU lattice according to claim 1, wherein In step S5, it also includes: S5.
1. First, the road test unit receives the signcryption message broadcast by the vehicle , and uses the decompression technology module to decompress the compressed ciphertext to obtain the ciphertext ; perform a polynomial multiplication operation on the ciphertext and the partial private key of the system private key with the modulus to obtain a random vector . After excluding the interference term in the ciphertext , an encoded message on the expandable lattice is obtained . By solving the closest vector pair on the expandable lattice for the encoded message , the decoded message is obtained, where the decoding function is ; S5.
2. After receiving the signcryption message sent by the vehicle, the road test unit verifies the signature. Through the dynamic ring sent by the vehicle, the road test unit obtains 8 public keys of vehicles , , , , , , , . Then, it successively verifies the difference between the blinded vector and the signature component for the 8 public keys of vehicles , the serial number of the current vehicle. If , is the allowed error, , the verification is successful and the decoded message is broadcast to other vehicles; otherwise, it returns verification failure.
Citation Information
Patent Citations
Lattice-based secret key packaging method
CN110460442A
Secret key packaging, encrypting and decrypting method based on NTRU grid
CN116318695A
Lattice-based car networking condition privacy protection message authentication method
CN118118901A
Digital Signature Technique
US20190020486A1