Security authentication system and method for space-air-ground fusion vehicle-mounted network based on double chains

Through the double-chain architecture and collaborative authentication mechanism, the problems of high latency, insufficient privacy protection and poor security of cross-domain authentication in the air-space and earth-integrated vehicle network are solved, and efficient and secure cross-domain authentication and key negotiation are achieved.

CN120498690AActive Publication Date: 2025-08-15TIANJIN CHENGJIAN UNIV +1

Patent Information

Application Number
CN202510990160.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-18
Publication Date
2025-08-15
Estimated Expiration
2045-07-18

AI Technical Summary

Technical Problem

The existing air-space integrated vehicle network authentication system has problems such as high delay, insufficient privacy protection, difficulty in adapting equipment due to resource constraints and poor security in high dynamics and cross-domain authentication.

Method used

A double-chain-based authentication system is adopted, including a ground authentication chain and a space authentication chain. Through the coordinated work of trusted institutions, roadside units, vehicle-side units, satellite nodes and drone nodes, cross-domain authentication and key negotiation are achieved using anonymous identity identifiers, elliptic curve certificate-free signatures, physical non-clone functions and threshold secret sharing algorithms.

Benefits of technology

It reduces cross-domain authentication delay, improves privacy protection, optimizes the authentication efficiency of resource-constrained devices, enhances the stability and attack resistance of the system, and ensures the efficiency and security of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498690A_ABST
    Figure CN120498690A_ABST
Patent Text Reader

Abstract

The invention provides a double-chain-based air-space-ground fusion vehicle-mounted network security authentication system and method, and belongs to the technical field of intelligent transportation, in an air-space-ground fusion vehicle-mounted network, a vehicle-mounted unit, a road side unit, an unmanned aerial vehicle node and a satellite node interact through a trusted mechanism and a double-chain architecture, after interaction in a single domain is completed, cross-domain interaction is performed, and the security authentication of the vehicle-mounted unit, the road side unit, the unmanned aerial vehicle node and the satellite node is completed. The authentication token is stored on the block chain after being obtained in the first interaction, and the quick interaction can be completed by directly calling the authentication token subsequently. According to the invention, through the double-chain block chain architecture, the authentication time delay is optimized, the cross-domain authentication efficiency is improved, and the privacy protection problem of the node in a high dynamic environment is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of intelligent transportation technology, and in particular relates to a dual-chain-based air-space-ground fusion vehicle-mounted network security authentication system and method. Background Art

[0002] With the rapid development of intelligent transportation systems, Space-Air-Ground Integrated Vehicular Networks (SAGIN), as one of the core technologies, is gradually becoming the infrastructure for the next generation of intelligent transportation systems, autonomous driving technology, and smart city construction.

[0003] Intelligent transportation systems rely on the Internet of Vehicles (IoV) to enable real-time communication between vehicles (V2V) and between vehicles and infrastructure (V2I). Core requirements include: low latency—autonomous driving requires millisecond-level responses (such as emergency braking commands); high reliability—communication interruptions can lead to traffic accidents; and privacy protection—preventing vehicle identity tracking and data leakage. However, dynamic topology changes (such as high-speed vehicles, drone formation adjustments, and satellite orbits) can render traditional authentication systems ineffective.

[0004] SAGIN integrates the communication networks of ground vehicles, drones and low-orbit satellites, and can provide extensive network coverage and efficient data transmission through the collaboration of three-layer networks: air, space and ground.

[0005] Specifically, SAGIN is a heterogeneous network architecture that integrates three types of communication nodes: satellites, drones, and ground vehicles. Satellites offer wide coverage, making them particularly suitable for remote areas or global communication scenarios (such as low-orbit satellites). Drones offer the advantage of flexible deployment, enabling the rapid establishment of temporary communication networks (such as in disaster response scenarios). Ground vehicles rely on roadside units (RSUs) and base stations for communication, requiring high-speed movement and complex environments. This network is suitable for scenarios requiring full coverage and dynamic communication, such as autonomous driving, smart cities, and disaster relief.

[0006] The advantages of this network architecture lie in its high dynamism and wide coverage, ensuring efficient and stable network communications even in situations such as high-speed vehicles, high-altitude drones, and constantly changing satellite orbits. However, this heterogeneous network environment also poses significant challenges, particularly in areas such as identity authentication, trust transfer, and privacy protection.

[0007] Currently, existing authentication schemes are typically based on public key infrastructure (PKI) authentication mechanisms. However, due to the highly dynamic nature of air-ground-integrated vehicular networks, PKI faces challenges in practical applications, such as high latency and frequent certificate updates. To address this, some schemes have attempted to incorporate blockchain technology for identity authentication. One approach, such as the one proposed by Xiong T et al., is a blockchain-based authentication mechanism that builds a consortium chain to store and authenticate identity information. This solution records authentication information on the blockchain, enabling each participating node to verify identity, thereby addressing certificate management and trust transfer issues. However, this approach still faces latency issues in cross-domain authentication and suffers from low verification efficiency when dealing with highly dynamic nodes. Alternatively, some schemes, such as Zhang Y et al., have proposed techniques based on anonymous credentials and dual-chain authentication, leveraging the decentralization and anonymity of blockchain to enhance privacy protection in identity authentication. These schemes provide good privacy protection in cross-domain authentication, but in a dynamic environment with frequent node changes, there is still significant room for improvement in authentication timeliness and cross-domain collaboration efficiency.

[0008] Therefore, the shortcomings of the prior art are mainly the following aspects:

[0009] 1. Shortcomings of Centralized Public Key Infrastructure (PKI) Authentication:

[0010] Traditional public key infrastructure (PKI) authentication systems typically rely on a certificate authority to manage the identity information and keys of all network nodes. However, this centralized authentication system has the following drawbacks:

[0011] (1) Frequent certificate updates lead to high latency: Due to the dynamic changes of nodes in the air-space-ground fusion network (such as the high mobility of satellite nodes and vehicle-mounted nodes), certificates need to be updated frequently, which increases the latency in the authentication process.

[0012] (2) Difficulty in cross-domain trust transfer: Although existing blockchain or blockchain-based authentication mechanisms can provide decentralized solutions, they still face high latency when processing cross-domain authentication. Between different network domains such as satellites, drones, and ground vehicles, the trust transfer and authentication process is limited by physical distance and latency, making it difficult to achieve efficient cross-domain authentication.

[0013] (3) Risks brought by centralized key management: The centralized management of key generation centers and certificate management centers makes the system vulnerable to single point failures. If these centers are attacked, the security of the entire system will be threatened.

[0014] 2. Insufficient privacy protection:

[0015] In existing authentication mechanisms, the identity information of nodes is often public during the authentication process, lacking sufficient privacy protection measures. This can lead to the following problems:

[0016] (1) Risk of identity information leakage: During the authentication process, the true identity of the node may be exposed, and attackers may use this information to track, locate, or launch attacks.

[0017] (2) Lack of dynamic identity protection: With the dynamic changes of nodes, it is difficult for traditional solutions to provide continuous and effective identity authentication while protecting node privacy.

[0018] 3. Low efficiency of cross-domain authentication:

[0019] The existing cross-domain authentication mechanism has the following problems when dealing with complex network topologies and dynamic nodes:

[0020] (1) Excessive authentication delay: Since the cross-domain authentication process requires the collaborative verification of multiple nodes and involves the exchange and processing of a large amount of data, the authentication delay is relatively high, which is not suitable for the low latency and high efficiency requirements in vehicle networks.

[0021] (2) Difficulty in adapting to resource-constrained devices: Most nodes in the air-space-ground integrated network (such as satellites, drones, and vehicles) have resource limitations (such as computing power and storage space), and existing authentication schemes are often difficult to execute efficiently on these nodes.

[0022] 4. Poor security and anti-attack capabilities:

[0023] Existing authentication systems often lack effective defense measures against replay attacks, man-in-the-middle attacks, and impersonation attacks. Especially in cross-domain authentication and highly dynamic node environments, attackers may exploit vulnerabilities in the authentication process to launch malicious attacks.

[0024] Therefore, a new authentication mechanism is needed to solve these technical difficulties and ensure network security and data privacy. Summary of the Invention

[0025] The problem to be solved by the present invention is to provide a dual-chain based air-space-ground integrated vehicle-mounted network security authentication system and method. By designing a layered heterogeneous authentication architecture, the authentication delay is optimized, the cross-domain authentication efficiency is improved, and the privacy protection problem of nodes in a highly dynamic environment is effectively solved.

[0026] To solve the above technical problems, the present invention adopts a technical solution: a dual-chain-based air-ground-integrated vehicle network security authentication system, comprising the following entities:

[0027] Trusted Authority (TA), including Key Generation Center (KGC) and Tracking Authority (TRA), responsible for global key management and identity tracing;

[0028] Roadside Unit (RSU), a semi-trusted node installed on roadside equipment that handles ground vehicle authentication and stores blockchain credentials;

[0029] Ground Base Station (GBS), which generates private keys for drones and supports group authentication;

[0030] On-board unit (OBU), a vehicle end node installed on a ground vehicle, interacting with the RSU or SN through an anonymous identity;

[0031] Satellite Node (SN), a node installed on a low-orbit satellite, provides cross-domain authentication support in the space-ground fusion network and generates satellite authentication tokens through threshold signatures;

[0032] Unmanned Aerial Vehicle (UAV) nodes are nodes installed on drones, responsible for providing air communications and authentication support, interacting with ground and other drones for identity authentication, supporting dynamic formations, and using physically unclonable function (PUF) hardware to bind identities;

[0033] The dual-chain architecture includes the ground authentication chain (TC) and the space authentication chain (SC). The ground authentication chain (TC) stores the anonymous identity hash values of vehicles and drones and the authentication tokens of the on-board units (OBUs) and unmanned aerial vehicle nodes (UAVs); the space authentication chain (SC) records the satellite authentication tokens distributed by satellite nodes to the on-board units (OBUs) to support satellite-ground collaborative authentication.

[0034] Furthermore, in the air-ground-integrated vehicle network, the on-board unit (OBU), roadside unit (RSU), unmanned aerial vehicle node (UAV) and satellite node (SN) interact through trusted institutions and a dual-chain architecture. After completing the interaction within a single domain, they conduct cross-domain interactions. The first interaction obtains the authentication token in the ground authentication chain belonging to their respective identities and stores it on the blockchain. Subsequently, the authentication token is directly called to complete fast interaction.

[0035] The present invention also provides a dual-chain-based air-ground-integrated vehicle network security authentication method, which includes the following steps:

[0036] The on-board unit (OBU) and the roadside unit (RSU) perform two-way identity interaction authentication: the vehicle (OBU) initiates an authentication request and sends its anonymous identity identifier (OBU-AID) and the current first timestamp (T1) to the roadside unit (RSU) to prevent replay attacks; the roadside unit (RSU) verifies the validity of the first timestamp (T1) and checks whether it exceeds the maximum transmission delay. If it does not time out, it calculates the signature verification equation to ensure the legitimacy of the vehicle identity; after verification, the RSU uploads the vehicle's authentication information to the ground authentication chain (TC), and generates an on-board unit authentication token (Token OBU) and returns it to the vehicle.

[0037] Furthermore, the RSU and OBU perform identity authentication through the elliptic curve certificateless signature mechanism, and use hash binding technology to ensure identity traceability.

[0038] When a drone group enters the ground authentication domain, it needs to authenticate with the roadside unit (RSU): the drone node (UAV) initiates an authentication request, providing its anonymous identity identifier (UAV-AID) and random number (R); the roadside unit (RSU) uses a physically unclonable function (PUF) to verify the drone's identity and generate a challenge-response value; the RSU returns an authentication response and stores the drone's authentication information in the ground authentication chain.

[0039] Furthermore, the authentication between the drone and the RSU adopts a hardware-level authentication mechanism based on PUF, which ensures the security and efficiency of the authentication process through hash operation and signature mechanism.

[0040] When a vehicle needs to access a satellite network, cross-domain authentication is required between the on-board unit (OBU) and the satellite node (SN): the on-board unit (OBU) initiates a cross-domain authentication request and sends its identity information and a third timestamp to the satellite node (SN); the satellite node (SN) generates a satellite authentication token for the on-board unit (OBU) and the unmanned aerial vehicle (UAV) and signs the satellite authentication token based on a threshold secret sharing algorithm; the SN sends the satellite authentication token back to the OBU to complete identity authentication and generate a session key.

[0041] Furthermore, the threshold secret sharing algorithm is used to implement a distributed authentication framework, which ensures the credibility and privacy protection of satellite authentication tokens through joint signatures by multiple satellite nodes.

[0042] Cross-domain authentication and key negotiation: After completing authentication within a single domain, cross-domain authentication and key negotiation are performed to ensure secure connections between different networks: the on-board unit (OBU) initiates an authentication request to the target cross-domain network and provides its on-board unit (OBU) authentication token; after receiving the request, the target network verifies the validity of the token and ensures that it is correct, generates a new session key, and performs key negotiation; once the negotiation is complete, all subsequent cross-domain communications will be encrypted using the session key to ensure the security and confidentiality of the communication.

[0043] Furthermore, cross-domain authentication tokens are managed through blockchain technology, and signature algorithms and hash binding technologies are used to ensure security during cross-domain communication.

[0044] Due to the adoption of the above technical solution, the present invention has the following beneficial effects:

[0045] (1) Efficient cross-domain authentication and trust transfer (certificateless cross-domain authentication mechanism of dual-chain collaborative architecture):

[0046] The present invention innovatively designs a dual-chain collaborative architecture, decoupling the heterogeneous models of the ground authentication chain and the space authentication chain, which are responsible for the identity authentication of ground nodes and satellite nodes respectively. In this way, the present invention can:

[0047] Reduce the latency of cross-domain authentication: The centralized management and certificate update process in traditional PKI authentication is reduced. Through dual-chain coordination and cooperation during cross-domain authentication, the parallel processing capability of the authentication process is greatly improved, thereby effectively reducing the latency of cross-domain authentication and achieving faster and more efficient cross-domain authentication.

[0048] Dynamic Trust Transfer: The dual-chain architecture enables efficient trust transfer between different domains (such as satellites, vehicles, and drones), without the limitations of traditional centralized authentication systems. The dual-chain architecture decouples satellite networks from ground-based vehicle networks, allowing independent authentication within each network domain, thereby improving the efficiency and security of cross-domain authentication.

[0049] It can be seen that the present invention can significantly improve the efficiency of cross-domain authentication, especially in highly dynamic, topologically complex air-space-ground integrated vehicle networks, and can quickly complete node identity authentication and trust transfer.

[0050] (2) Privacy protection and identity anonymity:

[0051] This invention uses a certificateless authentication mechanism and combines it with anonymous identity identifier technology to ensure the privacy protection of node identities. Through this design, the invention can:

[0052] Hiding true identity: Vehicles, drones, and satellite nodes use anonymous identity identifiers instead of real identity information when performing identity authentication, reducing the risk of identity information leakage.

[0053] Dynamically update identity information: Nodes can generate a one-time identity identifier during the authentication process, ensuring the privacy of identity information during each authentication process. Even if the node is active in the network for a long time, its identity is not easy to track, thus avoiding the privacy leakage caused by long-term use of the same identity identifier.

[0054] It can be seen that the present invention can effectively protect node privacy, ensure that the identity information of nodes such as vehicles, drones and satellites is concealed during the authentication process, and has the ability to dynamically update to prevent identity leakage.

[0055] (3) Efficient authentication of resource-constrained nodes:

[0056] Considering that nodes in the air-ground-space fusion network often have limited computing resources, this invention uses lightweight elliptic curve certificateless signature technology and physically unclonable functions (PUFs) to make the authentication process more lightweight, effectively saving computing resources and communication bandwidth to optimize authentication efficiency. Specifically, this invention can:

[0057] Reduced computational overhead: Certificateless signatures based on elliptic curves achieve identity traceability through hash binding technology, which not only reduces the complexity of certificate management but also improves the efficiency of the authentication process. In the highly dynamic environments of vehicle-mounted devices, drones, and satellite nodes, elliptic curve signature technology can provide efficient and secure authentication with limited computing resources.

[0058] Improved authentication speed: Utilizing Physically Unclonable Function (PUF) technology, hardware-level trusted binding can be achieved for drone groups, significantly enhancing authentication efficiency and security in dynamic group environments. As a hardware feature, PUF ensures the uniqueness and unforgeability of each drone's identity through its unique response characteristics, preventing malicious nodes from forging identities or joining a drone group. This eliminates the complex calculations required by traditional hardware security modules and enables the rapid generation of unique authentication credentials.

[0059] In addition, the use of physically unclonable function (PUF) technology can further enhance the uniqueness and difficulty of forgery of node identity, making privacy protection in the authentication process more solid.

[0060] It can be seen that the present invention operates efficiently in a resource-constrained environment, and uses technologies such as certificateless signature and PUF to ensure that identity authentication tasks can still be successfully performed on devices with limited computing and storage resources.

[0061] (4) System stability and reliability of cross-domain authentication:

[0062] Since the air-ground fusion network involves different types of nodes, such as satellites, drones, and ground vehicles, the changes in these nodes in the network topology are dynamic. Existing technologies have difficulty ensuring the stability and reliability of the system in cross-domain authentication. This paper introduces a threshold secret sharing algorithm to build a distributed authentication framework that can:

[0063] Enhanced system robustness: Through a distributed identity authentication framework, the system can maintain authentication functionality even if some nodes fail or are attacked. By distributing the generation and verification of satellite authentication tokens across multiple satellite nodes, efficient authentication and privacy protection are ensured, avoiding the security risks of a single node and improving the reliability and robustness of the entire authentication process.

[0064] Reducing cross-domain communication delay: The threshold secret sharing algorithm can quickly generate authentication credentials and effectively reduce cross-domain communication delay during authentication.

[0065] It can be seen that the present invention can improve the stability and reliability of the system, and through dual-chain collaboration and distributed authentication framework, ensure that the system can still maintain stable operation when facing cross-domain authentication and dynamic topology changes.

[0066] (5) Optimization of cross-domain authentication and key negotiation mechanisms:

[0067] This paper proposes an optimized cross-domain authentication and key agreement process, specifically for dynamic topologies and high mobility environments. This process enables fast and secure cross-domain authentication between nodes and generates session keys for encrypted communications. This mechanism enables seamless handover and efficient collaboration between different network domains (e.g., vehicles, drones, and satellites), ensuring data privacy and integrity during communications while reducing the complex key agreement steps and high computational overhead associated with traditional authentication schemes.

[0068] (6) Efficient cross-domain authentication token generation and verification process:

[0069] The authentication token generation and verification process proposed in this paper ensures system security and efficiency by generating a token after identity authentication at each node within the domain and performing verification during cross-domain handoffs. Especially when dealing with multiple authentication domains, after completing the initial authentication, all subsequent cross-domain authentications can be quickly completed using the generated token, avoiding repeated identity verification. The token generation and verification process significantly reduces authentication latency and improves the responsiveness of the entire system.

[0070] (7) Improved system security and anti-attack capabilities:

[0071] This invention introduces a timestamp verification mechanism into the authentication process, effectively preventing replay attacks. By adding timestamp information to each authentication request, each authentication request is ensured to be processed only within the valid period and automatically expires after a timeout, preventing historical authentication information from being maliciously replayed or tampered with.

[0072] By generating a unique signature value for each interaction and combining it with elliptic curve certificateless signature technology, the present invention effectively prevents forged identities and the entry of malicious nodes. Furthermore, the threshold secret sharing algorithm introduced in the present invention provides additional security for satellite node authentication, further enhancing the system's anti-attack capabilities.

[0073] (8) Improved scalability and adaptability of the authentication process:

[0074] The dual-chain blockchain collaborative authentication architecture proposed in this paper employs a distributed authentication strategy, eliminating the risk of single points of failure and flexibly adapting to changes in node topology. Leveraging the decentralized nature of blockchain technology, each node's authentication data is automatically verified and managed by smart contracts within the blockchain, rather than relying on a single key management center. This allows the system to maintain efficient authentication and low computational overhead as the number of nodes and network scale increase, ensuring the high scalability of the authentication mechanism.

[0075] In summary, this invention innovatively constructs a heterogeneous decoupled model (dual-chain blockchain architecture) between the space and ground authentication chains, ensuring the stability and reliability of the system in cross-domain authentication. To address the high mobility and resource constraints of vehicle nodes, an anonymous authentication mechanism based on elliptic curve certificateless signatures is designed, enabling identity traceability through hash binding. To meet the needs of group drone deployment, a lightweight group authentication protocol integrating a physically unclonable function (PUF) is proposed, combining timestamps and random numbers to generate dual privacy-preserving credentials. To address the periodic changes in satellite topology, a threshold secret sharing algorithm is introduced to construct a distributed authentication framework, effectively reducing cross-domain communication latency.

[0076] The authentication scheme of the present invention effectively overcomes the shortcomings of the existing technology and provides a more efficient, secure, reliable and scalable air-space-ground integrated vehicle network identity authentication mechanism, providing a solid technical guarantee for the security and credibility of the intelligent transportation system. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] The present invention will be described in detail below with reference to the accompanying drawings and in combination with examples, and the advantages and implementation modes of the present invention will become more apparent. The contents shown in the accompanying drawings are only used to illustrate the present invention and do not constitute any limitation to the present invention. In the accompanying drawings:

[0078] Figure 1 Schematic diagram of the system of the present invention.

[0079] Figure 2 It is an interactive flow chart of the present invention. DETAILED DESCRIPTION

[0080] like Figure 1 As shown, the present invention provides a dual-chain-based air-ground-integrated vehicle network security authentication system, including the following entities:

[0081] Trusted Authority (TA), including Key Generation Center (KGC) and Tracking Authority (TRA), responsible for global key management and identity tracing;

[0082] Roadside Unit (RSU), a semi-trusted node installed on roadside equipment that handles ground vehicle authentication and stores blockchain credentials;

[0083] Ground Base Station (GBS), which generates private keys for drones and supports group authentication;

[0084] On-board unit (OBU), a vehicle end node installed on a ground vehicle, interacting with the RSU or SN through an anonymous identity;

[0085] Satellite Node (SN), a node installed on a low-orbit satellite, provides cross-domain authentication support in the space-ground fusion network and generates satellite authentication tokens through threshold signatures;

[0086] Unmanned Aerial Vehicle (UAV) nodes are nodes installed on drones, responsible for providing air communications and authentication support, interacting with ground and other drones for identity authentication, supporting dynamic formations, and using physically unclonable function (PUF) hardware to bind identities;

[0087] The dual-chain architecture includes the ground authentication chain (TC) and the space authentication chain (SC). The ground authentication chain (TC) stores the anonymous identity hash values of vehicles and drones and the authentication tokens of the on-board units (OBU) and unmanned aerial vehicles (UAVs); the space authentication chain (SC) records the satellite authentication tokens distributed by satellite nodes to the on-board units (OBUs) to support satellite-ground collaborative authentication.

[0088] The present invention also provides a dual-chain-based air-ground-integrated vehicle network security authentication method, which includes the following steps:

[0089] In the integrated air-ground-space vehicle network, the on-board unit (OBU), roadside unit (RSU), unmanned aerial vehicle node (UAV) and satellite node (SN) interact through the system's authentication scheme. After completing the interaction within a single domain, they conduct cross-domain interaction. In the first interaction, the authentication token in the ground authentication chain belonging to their respective identities is obtained and stored on the blockchain. Subsequently, the authentication token is directly called to complete fast interaction.

[0090] Specifically, the on-board unit (OBU) and the roadside unit (RSU) perform two-way identity interactive authentication: the vehicle (OBU) initiates an authentication request and sends its anonymous identity identifier (OBU-AID) and the current first timestamp (T1) to the roadside unit (RSU) to prevent replay attacks; the roadside unit (RSU) verifies the validity of the first timestamp (T1) and checks whether it exceeds the maximum transmission delay. If it does not time out, it calculates the signature verification equation to ensure the legitimacy of the vehicle's identity; after verification, the RSU uploads the vehicle's authentication information to the ground authentication chain (TC), and generates an on-board unit authentication token (Token OBU) and returns it to the vehicle.

[0091] The RSU and OBU perform identity authentication through the elliptic curve certificateless signature mechanism, and use hash binding technology to ensure identity traceability.

[0092] The OBU-AID (Oblivious Vehicle Identity Identifier) ensures the privacy of the vehicle's identity through a generated anonymous identifier. The first timestamp (T1) verifies the freshness of the message and prevents replay attacks. The signature value uses the vehicle's private key to sign the authentication information, ensuring its authenticity and integrity.

[0093] When a drone group enters the ground authentication domain, it needs to authenticate with the roadside unit (RSU): the drone node (UAV) initiates an authentication request, providing its anonymous identity identifier (UAV-AID) and random number (R); the roadside unit (RSU) uses a physically unclonable function (PUF) to verify the drone's identity and generate a challenge-response value; the RSU returns an authentication response and stores the drone's authentication information in the ground authentication chain.

[0094] The authentication between the drone and the RSU adopts a hardware-level authentication mechanism based on PUF, which ensures the security and efficiency of the authentication process through hash operation and signature mechanism.

[0095] The UAV Anonymous Identifier (UAV-AID) ensures the privacy of the drone's identity through an anonymous identifier. The Random Number (R) ensures authentication security and freshness for each session. The Physical Unclonable Function (PUF) Response Value (RPUF) leverages hardware-level PUF properties to ensure uniqueness and unforgeability.

[0096] When a vehicle needs to access a satellite network, cross-domain authentication is required between the on-board unit (OBU) and the satellite node (SN): the on-board unit (OBU) initiates a cross-domain authentication request and sends its identity information and a third timestamp (T3) to the satellite node (SN); the satellite node (SN) generates a satellite authentication token for the on-board unit (OBU) and the unmanned aerial vehicle (UAV) and signs the satellite authentication token based on a threshold secret sharing algorithm; the SN sends the satellite authentication token back to the OBU to complete identity authentication and generate a session key.

[0097] The threshold secret sharing algorithm is used to implement a distributed authentication framework, which ensures the credibility and privacy protection of satellite authentication tokens through joint signatures by multiple satellite nodes.

[0098] Satellite authentication token (Token SN): The satellite node generates an authentication token and ensures its security through a threshold signature mechanism. Session key (K_session): The key used to encrypt communications and ensure confidentiality. Third timestamp (T3): Ensures message timeliness and prevents replay attacks.

[0099] Cross-domain authentication and key negotiation: After completing authentication within a single domain, cross-domain authentication and key negotiation are performed to ensure secure connections between different networks: the on-board unit (OBU) initiates an authentication request to the target cross-domain network and provides the on-board unit (OBU) authentication token it has obtained; after receiving the request, the target network verifies the validity of the token and ensures that it is correct, generates a new session key, and performs key negotiation; once the negotiation is complete, all subsequent cross-domain communications will be encrypted using the session key to ensure the security and confidentiality of the communication.

[0100] Cross-domain authentication tokens are managed through blockchain technology, and signature algorithms and hash binding technologies are used to ensure security during cross-domain communication.

[0101] Among them, the cross-domain authentication token is used to verify the trust relationship between different domains. The session key (K_session) is used to encrypt the communication key to ensure the confidentiality of the communication.

[0102] Furthermore, the authentication scheme of the system includes the following steps:

[0103] S1. System initialization:

[0104] System input security parameters , a prime number is generated by the trusted agency TA (q is the order of the cyclic group, which is used to define the size of the group and the output range of the hash function), let yes Finite fields on , Denotes the size of the finite field. Let It is an elliptic curve (a group that contains the basic points used for encryption and decryption) points, (A basic point in group G, used to generate public and private keys) is The generator of yes Select a random number As the private key of KGC (GBS's private key, used to generate GBS's public key), and calculate As the public key of KGC (used for encryption and decryption operations); select a random number TRA's private key, calculate TRA's corresponding public key GBS selection For its private key (used to calculate the public key corresponding to GBS), calculate The public key corresponding to GBS (other entities can use this public key to verify the identity of GBS or encrypt information to GBS). At the same time, TA defines the collision hash function (Map the elements of group G to ), (Combine binary data of any length with elements in group G and map them to ), (Combining binary data of arbitrary length, two elements in group G and another binary data, mapping to ), (Map binary data of arbitrary length directly to Therefore, the common parameter set of the system is ,in, To represent the set of all hash functions H0, H1, H2, H3, sp represents the public parameter set sent by the system to the entity, the public parameter set is distributed to each entity layer through a secure channel for pre-storage, and the system locally secretly stores the private key , where sk represents the system's private key set, which is stored locally in the system.

[0105] S2. Registration Verification:

[0106] During the registration and verification phase, physical nodes such as RSU, OBU, UAV, and SN must obtain anonymous identities from security agencies in advance and complete identity registration. This ensures the authenticity and privacy of the node's identity, laying the foundation for subsequent security authentication and information exchange.

[0107] RSU registration: RSU provides necessary registration information, including real identity identification, when registering with the trusted agency TA And other relevant information, after TA receives and verifies, TRA stores the real identity of RSU ,in Indicates a connection symbol, and others indicates other relevant information required for registration; then, KGC randomly selects As the private key of RSU, and calculate is the public key of RSU; TA sets the public parameter Send it to RSU for pre-storage, and RSU will send the public key Upload to the ground certification chain for storage.

[0108] OBU registration: When an OBU enters the air-ground signal domain for the first time, it needs to register its identity information. The user needs to enter the identity information , the vehicle-mounted device synchronously collects the user's fingerprint information With voice message , together constitute the real identity information set of OBU ; Then, OBU selects a random number , used to generate each pseudonym to ensure uniqueness, and complete the anonymous identity calculation of OBU according to formula (1):

[0109] (1)

[0110] In formula (1), The validity period of the OBU anonymous identity, PID1 represents the fixed part of the pseudonym, which is used to quickly identify the anonymous identity of the OBU, and PID2 represents the dynamic part of the pseudonym, which ensures the uniqueness and timeliness of the pseudonym. Therefore, the pseudonym of the OBU is expressed as The pseudonym is valid for a single use and must be updated in a timely manner after a specified period of time to ensure identity anonymity and security.

[0111] After the anonymous identity is obtained, a local private key is generated, and KGC receives the OBU anonymous identity submitted by TRA , select a random number ,The random number here is used to calculate the partial private key. ,According to formula (2), the partial private key of OBU is calculated. ,A,B are used to calculate the intermediate value of the partial private key. ,A, is the elliptic curve point calculated based on the ,system parameters, and is used to generate the intermediate value associated with the ,OBU identity. B, ensures that the private key is associated with the ,identity. (2)

[0112] KGC will It is sent to OBU through a secure channel, and after receiving it, OBU needs to check it through formula (3) Is it true to verify the validity of the local private key? If it is true, Stored in the OBU, otherwise an error message is returned and the registration process is terminated.

[0113] (3)

[0114] After obtaining the local private key, the OBU selects a random secret value , used to calculate the partial private key of OBU, and calculate the complete private key and public key of OBU according to formula (4):

[0115] (4)

[0116] After the above process, the public key pair of OBU is finally determined to be ,in Indicates the public key 1 of OBU, Indicates the public key 2 of OBU, and the two together constitute the public key pair of OBU; the private key pair is finally determined ,here Indicates the private key 1 of OBU, The two together constitute the OBU private key pair. This completes the construction of the key pair.

[0117] UAV registration: When a UAV initiates registration, it first selects its own unique identity , and sends a registration request to GBS. GBS, as the core processing node of the registration process, first calculates the anonymous identity of the drone, that is, (in Indicates the validity period of the anonymous identity, used to ensure the freshness of the identity). After the anonymous identity is generated, GBS verifies the legitimacy of the drone identity and generates a long-term private key for the UAV after the verification passes. , and based on the elliptic curve cryptography, calculate the associated public key To enhance communication security and flexibility, GBS selects random numbers As the UAV temporary private key and synchronous calculation is the temporary public key of UAV; GBS calculates , y is used as the UAV certificate, which is used as the UAV registration credential; after completing the above calculation, GBS records the current second timestamp T2 and sends the registration response packet It is sent to the UAV through a secure transmission channel. After receiving the information, a legitimacy check is performed to ensure data integrity and source reliability. Specifically, the UAV first verifies If the verification fails, the UAV discards the received information to avoid security risks; if the verification passes, the valid data is retained and the subsequent security negotiation process begins.

[0118] (5)

[0119] At this time, the UAV generates a challenge value , and calculate the UAV response value with the help of Physical Unclonable Function (PUF) , and then construct the privacy protection parameters through hash and XOR operations , Indicates an XOR operation. Finally, the UAV stores key registration parameters locally. , complete the registration process and establish a secure foundation for subsequent access to the network and participation in communications.

[0120] SN registration: When the satellite node SN starts the registration process, it first selects a random number (used to generate SN temporary parameters and private key calculation), calculate (As a temporary parameter of SN for subsequent message verification calculation), and generate anonymous information at the same time ,in and They are the real identity of SN and the identity after anonymization. After completing the identity preprocessing, SN sends To TRA, TRA uses XOR operation to restore the true identity of SN after receiving it , and establish a "real identity-anonymous identity" mapping relationship locally for subsequent identity tracing and management; after the identity mapping is established, KGC intervenes in the private key generation process, and KGC selects a random number and calculate , where r is used to temporarily calculate the parameter R, which is used to form the subsequent SN private key and generate the private key corresponding to the SN To ensure the security of private key transmission, KGC performs privacy protection on the private key and calculates , where tmp is used to obfuscate the private key and then the encrypted private key parameters After receiving the KGC response, SN performs the private key decryption and verification operation. First, it calculates Get the private key and save it. SN can be verified by formula (6) Verify the correctness of the private key.

[0121] (6)

[0122] If true, it indicates that there is no tampering or error in the private key generation and transmission process, and the satellite node completes the private key storage; otherwise, the registration process needs to be reinitiated.

[0123] S3, access authentication:

[0124] During the access authentication phase, the OBU completes identity authentication and generates an OBU authentication token and an SN authentication token through the initial interactive authentication with the air-ground network and the space-based network. The authentication token will be used for subsequent cross-domain network switching authentication to ensure the security and seamless connection of the system between different network domains.

[0125] Bidirectional authentication between OBUs and RSUs: When a user initiates a request to access air-ground information network resources, they must first complete bidirectional authentication with the surrounding roadside units (RSUs). Once authenticated, the RSU generates and uploads a credential for the vehicle to the ground blockchain. This credential supports subsequent cross-domain and cross-heterogeneous network authentication scenarios, building a foundation for global trusted authentication.

[0126] When OBU initiates a signature authentication request When, based on anonymous identity Record the current timestamp , and then calculate according to formula (7):

[0127] (7)

[0128] Where h represents the intermediate value used by OBU for signature calculation. As the signature value, OBU sends the message tuple Send to the adjacent RSU or other OBU.

[0129] After receiving the message from the OBU, the neighboring RSU first records the current timestamp To verify the freshness of the message, if ( is the maximum transmission delay allowed by the system), the message is determined to have timed out and a delay alarm is returned; otherwise, a deep verification is performed: calculation recovery and , verified by formula (8) Is it established? If so, the RSU receives the authentication message; otherwise, it returns an error message and terminates the network access process.

[0130] (8)

[0131] After RSU completes the network authentication of OBU, it generates a blockchain certificate for it ,calculate Upload to the ground certification chain for storage. The certificate covers the complete certification information of the vehicle, and then RSU generates a random number , record the current timestamp , perform the following calculations in sequence: , , , , where R is used for subsequent verification calculation of OBU, C1 uses XOR calculation to generate a confidential value for R, and C2 uses XOR calculation to generate a confidential value for m OBU Generate a secret value and construct the RSU signature through private key calculation Finally, RSU sends the message Send to OBU.

[0132] After receiving the authentication message from RSU, OBU records the current time ,like , then the message is judged to have timed out and a timeout alarm is returned; if it is established, the message is accepted. If the freshness check passes, OBU performs the reverse operation and uses P to calculate , get and , then verify the formula according to formula (9) Is it true? If so, OBU determines that RSU is trustworthy and stores the hash value of the OBU authentication token ; Otherwise, reject the authentication message.

[0133] (9)

[0134] At this point, the OBU and RSU complete their initial mutual authentication, granting the OBU network access permission. After the OBU is authenticated by the RSU, its anonymous identity information and the OBU authentication token are stored synchronously on the ground authentication chain, providing trust credentials for subsequent cross-domain interactions. Once the ground authentication chain verifies the token's legitimacy, the blockchain node uses the unauthenticated OBU authentication token as a transaction, generating a new blockchain block and broadcasting it to the authentication chain network. Once the network nodes reach consensus using the PBFT consensus algorithm, the user successfully connects to the air-ground network, gaining access to RSU resources and UAV group resources within the area and the ability to conduct mission interactions.

[0135] UAV and RSU Bidirectional Authentication: Drones have lightweight computing and storage capabilities. When a drone group enters a new trust domain and prepares to communicate with entities within the domain, it must first complete authentication with the RSU in range and obtain a UAV authentication token. Once authenticated, the UAV can use this token to establish secure communication with other entities in the domain and provide services.

[0136] The UAV first calculates the PUF response verification value before entering the authentication process , and recover your own private key . Then, the UAV selects a random number , used to generate the UAV temporary parameter R, ensure the uniqueness and security of each authentication request, and generate the timestamp at this time , calculate in sequence 、 As the signature factor of UAV, it is used to generate a signature and combine the private key and certificate parameters to generate a signature Finally, the drone will authenticate the message Sent to RSU.

[0137] After a while, when the RSU receives the authentication request sent by the drone cluster, it first verifies the timestamp The freshness, through Determine the timeliness of the message. If the freshness check passes, RSU is calculated , according to formula (10) verification formula If so, the RSU accepts the UAV authentication request within the range; otherwise, it rejects the authentication to ensure the security baseline of intra-domain communication.

[0138] (10)

[0139] When the UAV passes the RSU authentication for the first time, the RSU endorses the UAV anonymous identity, incorporates the group serialized identity list into the ground authentication chain, and generates a UAV authentication token for the drone group. , obtained after hash operation (represents the hash value calculated by the token), RSU selects a random number (used to construct signatures), construct double-signed messages , used to bind the public key of RSU; , used to bind the UAV authentication token hash value, where is the current timestamp. After completing the signature construction, RSU broadcasts the message packet To drone swarms.

[0140] When the drone group receives the message, according to formula (11) Is it true? If so, the drone group stores the UAV authentication token hash value Otherwise, the message is discarded and the authentication process is terminated.

[0141] (11)

[0142] At this point, the UAV and RSU have completed their first mutual authentication. After the UAV is authenticated by the RSU, its anonymous identity information and the hash value of the UAV authentication token are stored synchronously in the ground-based authentication chain, providing trust support for cross-domain interactions. At this point, the UAV fleet has successfully connected to the airborne network and is capable of providing services to OBUs within range, enabling the coordinated expansion of services across heterogeneous air-ground networks.

[0143] UAV, OBU, and SN Authentication: In an integrated space-ground network architecture, the movements of OBUs and UAVs are highly random and unpredictable, whereas satellite nodes, due to their strict orbital operation, exhibit periodic and predictable topological changes. Due to this characteristic, when ground nodes connect to space-based networks, their switching behavior exhibits significant regularity. To enable efficient and secure connection between drones or vehicles and space-based satellite networks, threshold signature technology is introduced to generate a universal satellite network authentication token, providing trusted credentials for subsequent handovers across satellite networks.

[0144] The space authentication chain uses a threshold signature mechanism to issue satellite authentication tokens. The threshold is set to t, n is the total number of key distributions, and λ is a security parameter, usually representing a binary string of length λ. Initially, the space authentication chain executes Algorithm to generate satellite threshold public key And the on-chain private key of each satellite node When an OBU or UAV needs to access the space-based network, it initiates an authentication request to the SN within the network coverage. After receiving the request, the SN first verifies the identity of the UAV or OBU node through the above predefined process, and then generates Satellite authentication tokens, including satellite authentication tokens for accessing the satellite network and the integrity signature of the certificate. Broadcast to the space authentication blockchain and trigger the blockchain consensus mechanism. After receiving the broadcast through the PBFT consensus algorithm, other SN nodes on the chain call the satellite node public key stored in the blockchain for verification. If the token is issued, the integrity of the right Sign and generate partial signature Then send it to the satellite node SN. When the number of valid signatures collected by the SN that initiates the broadcast When the threshold aggregation algorithm is used to combine the multi-node partial signatures into the final verifiable satellite authentication token ,ensure that the satellite authentication token generation process meets the threshold security requirements.

[0145] After completing the aggregation of satellite authentication tokens, SN selects a random number calculate , K represents the temporary parameter for SN verification, for satellite authentication token Signed , then send a message To the application node.

[0146] When the OBU or UAV receives the message, it first verifies the timestamp The validity of 、 , where α is used to bind the anonymous identity of SN, and β is used to bind the satellite authentication token and the temporary verification parameter K. According to formula (12), the judgment formula Is it established? If so, the access authentication is passed and node storage is applied. As a space-based network access credential; otherwise, the access request is denied.

[0147] (12)

[0148] Through the above process, the space-based network and the ground-based network (the network where the OBU and UAV are located) are securely connected, achieving trusted interconnection between heterogeneous networks across domains. After the above authentication process, the air-ground-ground integrated vehicle network completes network access authentication.

[0149] like Figure 2 As shown in the figure, OBUs connected to the network coverage can rely on the established security trust mechanism to apply for the use of integrated air-space-ground network resources to achieve interconnection and interoperability in a multi-domain heterogeneous network environment, laying a solid security and trustworthy foundation for subsequent cross-domain business collaboration and data interaction of the Internet of Vehicles.

[0150] S4, dynamic switching:

[0151] In the air-space-ground-integrated vehicle network scenario, when the OBU node performs cross-domain operations or performs network switching to access air-space-ground-network resources, it can use the identity token obtained during the network access phase to efficiently implement rapid switching of network connections and achieve low-latency switching effects, which meets the high real-time requirements of the Internet of Vehicles.

[0152] The key negotiation mechanism in the switching phase is designed to ensure the security and reliability of network collaboration in cross-domain scenarios and provide support for the smooth transition of multi-domain heterogeneous networks.

[0153] During the air-ground network switching phase, when the OBU wants to use the ground-based network across domains or switch to the air-based network, since the anonymous identity and authentication information of the OBU in the first authentication phase have been stored in the ground authentication chain, the secondary authentication can be completed through lightweight interaction. When the OBU submits a cross-domain authentication request, the RSU accepts it and sends a random number to the vehicle. , used to ensure the freshness of the request, and then the OBU Generate signature , the message package Sent to the RSU node.

[0154] RSU checks after receiving the message The timeliness and legality of the OBU token are then checked through the ground authentication chain. If the query has no result, the authentication is judged to have failed and a failure response is returned; if the query is successful, the OBU completes the air-ground network handover and enters the session key negotiation phase.

[0155] In the key negotiation process, the RSU connected to the air-ground network generates a session group proposal periodically, broadcasts a session request to the OBU and UAV within the range, and sets a participation time window T tmp. After authentication is passed, the RSU generates a session key and encrypt the random number with the session key ,calculate For encryption , and then encrypt them with the public keys of OBU and UAV respectively and the RSU's public key , which are then sent to OBUs and UAVs within range.

[0156] After receiving the message, UAV and OBU each use their own private key to decrypt and obtain and , synchronization check After the authentication is passed, OBU and UAV will obtain the group session key. The validity period of the OBU is 100%, and nodes within the range are supported to update the session key at intervals to ensure communication security and freshness. At this point, the OBU completes the air-ground network signal domain switching and has cross-domain interaction capabilities, realizing secure communication and resource collaboration in the vehicle-drone cross-domain scenario.

[0157] In the space-based network switching scenario, when the OBU needs to perform the SN replacement operation, the OBU calls its own private key to obtain the satellite authentication token. The SN constructs an authentication message M and sends it to the target SN node. Upon receiving the message, the SN follows the space-based network authentication logic and first queries the blockchain system for the hash value corresponding to the satellite authentication token. The token's legitimacy and validity are confirmed through hash checksum and signature verification. If verification succeeds, the SN grants the OBU space-based network access, completing the cross-domain handover. If verification fails, the handover process is terminated and an error response is returned.

[0158] Example:

[0159] Assume that in an air-ground-integrated vehicle network scenario, the OBU needs to enter the air-ground-integrated network through the RSU. The entire authentication process is as follows:

[0160] Certification of OBU and RSU:

[0161] The OBU sends an authentication request to the RSU by generating an anonymous identity identifier (AID) with the current timestamp (T);

[0162] RSU verifies the validity of the timestamp, calculates the signature and performs authentication;

[0163] After RSU verification, an OBU authentication token is generated and uploaded to the ground authentication chain.

[0164] OBU and SN authentication:

[0165] When entering the satellite network, the OBU sends a cross-domain authentication request to the SN and provides a satellite authentication token (Token SN).

[0166] The SN generates an SN authentication token and signs it using the threshold secret sharing algorithm, generates a new session key and returns it to the OBU.

[0167] Cross-domain authentication and key negotiation:

[0168] The OBU uses the obtained SN authentication token to authenticate with the SN. After the authentication is successful, a session key is generated to ensure the encryption and security of subsequent communications.

[0169] Final certification and communication:

[0170] All authentication data and generated session keys are stored and verified through the blockchain, ensuring the credibility of cross-domain authentication and ensuring data integrity and privacy protection during communication.

[0171] The embodiments of the present invention are described in detail above, but the contents are only preferred embodiments of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the present invention.

Claims

1. A dual-chain, air-ground, and space-integrated vehicle network security authentication system, characterized by: Includes the following entities: Trusted institutions, including key generation centers and tracking institutions, are responsible for global key management and identity tracing; Roadside Units (RSUs), semi-trusted nodes installed on roadside equipment, handle ground vehicle authentication and store blockchain credentials; Ground base station, generates private keys for drones and supports group authentication; On-board unit, a vehicle end node installed on a ground vehicle, interacting with the RSU or SN through an anonymous identity; Satellite nodes are nodes installed on low-orbit satellites. They provide cross-domain authentication support in the space-ground fusion network and generate satellite authentication tokens through threshold signatures. The drone node is a node installed on the drone, responsible for providing air communication and authentication support, interacting with the ground and other drones for identity authentication, supporting dynamic formations, and using physical unclonable function hardware to bind identities; Dual-chain architecture, including ground authentication chain and space authentication chain. Ground authentication chain: stores the anonymous identity hash values of vehicles and drones and the authentication tokens of vehicle-mounted units and drone nodes; Space authentication chain: records the satellite authentication tokens distributed by satellite nodes to the on-board units, supporting satellite-ground collaborative authentication.

2. The dual-chain-based air-ground-integrated vehicle network security authentication system according to claim 1 is characterized by: In the air-ground-integrated vehicle network, the on-board unit, roadside unit, drone node and satellite node interact through trusted institutions and a dual-chain architecture. After completing the interaction within a single domain, they conduct cross-domain interaction. The first interaction obtains the authentication token in the ground authentication chain belonging to their respective identities and stores it on the blockchain. Subsequently, the authentication token is directly called to complete fast interaction.

3. A dual-chain, air-space-ground fusion vehicle network security authentication method, implemented by the dual-chain, air-space-ground fusion vehicle network security authentication system according to claim 1 or 2, characterized in that: The following steps are involved: The OMU and the RSU perform two-way identity authentication: the vehicle initiates an authentication request and sends its anonymous identity identifier and current timestamp to the RSU to prevent replay attacks; The RSU verifies the validity of the first timestamp and checks whether the maximum transmission delay has been exceeded. If not, it calculates the signature verification equation to ensure the legitimacy of the vehicle identity. After verification by the road test unit, the vehicle's authentication information is uploaded to the ground authentication chain, and an on-board unit authentication token is generated and returned to the vehicle; When a drone group enters the ground authentication domain, it needs to authenticate with the roadside unit: the drone node initiates an authentication request, providing its anonymous identity identifier and random number; The RSU uses a physically unclonable function to verify the drone's identity and generate a challenge-response value. The RSU returns an authentication response and stores the drone's authentication information in the ground authentication chain. When a vehicle needs to access a satellite network, cross-domain authentication is required between the vehicle unit and the satellite node: the vehicle unit initiates a cross-domain authentication request and sends its identity information and a third timestamp to the satellite node; The satellite node generates satellite authentication tokens for the vehicle-mounted unit and the UAV node, and signs the satellite authentication tokens based on the threshold secret sharing algorithm; The satellite node sends the satellite authentication token back to the onboard unit to complete identity authentication and generate a session key; Cross-domain authentication and key negotiation: After completing authentication within a single domain, cross-domain authentication and key negotiation are performed to ensure secure connections between different networks: the on-board unit initiates an authentication request to the target cross-domain network and provides the on-board unit authentication token it has signed for; after receiving the request, the target network verifies the validity of the token and ensures that it is correct, generates a new session key, and performs key negotiation; once the negotiation is complete, all subsequent cross-domain communications will be encrypted using the session key to ensure the security and confidentiality of the communication.

4. The dual-chain-based air-ground-integrated vehicle network security authentication method according to claim 3 is characterized by: The roadside unit and the on-board unit perform identity authentication through an elliptic curve certificateless signature mechanism, and utilize hash binding technology to ensure identity traceability.

5. The dual-chain-based air-ground-integrated vehicle network security authentication method according to claim 3 is characterized by: The authentication between the UAV and the roadside unit adopts a hardware-level authentication mechanism based on a physically unclonable function, and ensures the security and efficiency of the authentication process through hash operations and signature mechanisms.

6. The dual-chain-based air-ground-integrated vehicle network security authentication method according to claim 3 is characterized by: The threshold secret sharing algorithm is used to implement a distributed authentication framework, and multiple satellite nodes jointly sign to ensure the credibility and privacy protection of the authentication token.

7. The dual-chain-based air-ground-integrated vehicle network security authentication method according to claim 3 is characterized by: Cross-domain authentication tokens are managed through blockchain technology, and signature algorithms and hash binding technologies are used to ensure security during cross-domain communication.

Citation Information

Patent Citations

  • Spatial information network access control system and authentication method based on blockchain

    CN112564775A

  • Identity-based authentication method for space-based network

    CN113079016A

  • High-speed station detection auxiliary system and method thereof

    CN115457689A

  • Cross-domain authentication method of space-ground integrated Internet of Vehicles based on alliance block chain

    CN116260592A

  • Method for secure vehicular communications and methods for pedestrian and vehicle location validation

    WO2021083557A1

Cited By

  • Unmanned aerial vehicle cluster task collaboration method based on block chain

    CN120803057A

  • Block chain-based Web3.0 access node switching method and spatial information network system

    CN121510200A

  • Mesh networking and satellite communication-based fusion system

    CN121791926A