Physical security Internet of Vehicles multi-receiver authentication scheme
By combining the Chinese Remainder Theorem and certificate-free cryptography to design a multi-receiver authentication method, and incorporating Physically Unclonable Functions (PUFs) and fuzzy extraction techniques, the flexibility and security issues of multi-receiver authentication in vehicular ad hoc networks are solved, achieving efficient multi-receiver authentication and key protection.
Patent Information
- Application Number
- CN202511127843.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2025-11-07
AI Technical Summary
Existing multi-receiver authentication schemes in vehicular ad hoc networks suffer from insufficient communication flexibility, high computational costs, and vulnerability to key attacks. In particular, in resource-constrained vehicle environments, it is difficult to guarantee security and efficiency.
By combining the Chinese Remainder Theorem with certificate-free cryptography, a multi-receiver authentication method is designed. It incorporates Physically Unclonable Functions (PUFs) and fuzzy extraction techniques, allowing vehicles to generate private keys on demand. These keys are then revoked and verified by a Certificate Authority (CA), avoiding long-term key storage and enhancing system security.
It enables flexible multi-receiver authentication without the need to specify the recipient in advance, reduces computational costs, improves revocation efficiency, prevents key attacks, and enhances system security and communication efficiency.
Smart Images

Figure CN120916151A_ABST
Abstract
Description
Technical Field
[0002] This invention relates to the field of vehicle network security technology, specifically to the security of vehicle-to-vehicle communication information, and a signature and authentication method when a vehicle needs to send messages to multiple nearby vehicles. Background Technology
[0004] Against the backdrop of a broad outlook for latency-sensitive services in future sixth-generation (6G) wireless communication networks, vehicles have become the world's third-largest mobile terminal. At the same time, this has brought about some problems, such as traffic congestion, traffic accidents, and more complex traffic conditions. To address these issues, critical information such as vehicle location, weather conditions, and road conditions must be shared in real time between vehicles and neighboring vehicles or roadside units (RSUs).
[0005] As an important component of intelligent transportation systems, vehicular ad hoc networks (VANETs) have received widespread attention from academia and industry. For example... Figure 1 As shown, vehicular ad hoc networks typically consist of three components: a certification authority (CA), vehicles equipped with onboard units (OBUs), and roadside units (RSUs). The two main communication types in vehicular ad hoc networks are vehicle-to-vehicle (V2V) communication and vehicle-to-infrastructure (V2I) communication. According to the definition in IEEE standard 1609.2, both communication types follow dedicated short-range communication protocols used for wireless access in vehicular ad hoc networks [1-2]. However, due to the openness of wireless channels in vehicular ad hoc networks, attackers can easily launch various attacks. Therefore, the security of data transmission in vehicular ad hoc networks has become one of the main tasks for researchers.
[0006] Multi-receiver communication (MRF) is a fundamental communication mode in vehicular ad hoc networks (VANs), where messages are typically transmitted wirelessly by resource-constrained terminals. To ensure the security of MRF, several authentication schemes have been introduced [3-7]. However, each of these schemes presents its own challenges. For example, the sender must specify the receiver when transmitting information, which significantly impacts communication flexibility. In some schemes [4-7], communication overhead increases with the number of receiving terminals, leading to higher transmission costs when the number of terminals is large. Schemes [4-5] employ bilinear mapping for MRF authentication. However, the high computational cost of bilinear mapping makes these schemes unsuitable for VANs with limited computational resources and stringent time efficiency requirements. Therefore, designing a secure and lightweight MRF authentication mechanism for VANs has considerable application value.
[0007] On the other hand, the traditional solution assumes that the key of the vehicle is securely stored in an ideal tamper-resistant device, and this device must never be compromised by an attacker. In fact, an attacker can still obtain the key stored in the tamper-resistant device through a side-channel attack. Once the key is obtained, it becomes easy to decrypt the encrypted information.
[0008] In recent years, a physical unclonable function (PUF) is considered as a promising tool to resist side-channel attacks [8]. A physical unclonable function can map a set of challenges to a set of responses based on an extremely complex physical system. In addition, the randomness of the integrated circuit manufacturing process leads to unique and unclonable characteristics. Therefore, the challenge-response generated by the physical unclonable function is also unique. Taking advantage of this feature, the vehicle can use its challenge-response pair to uniquely identify and generate its key in real time, so that each terminal does not need to store the key in the tamper-resistant device for a long time.
[0009] [1] J. B. Kenney, “Dedicated short-range communications (dsrc)standards in the united states,” Proceedings of the IEEE, vol. 99, no. 7, pp.1162–1182, 2011.
[0010] [2] D. Jiang and L. Delgrossi, “Ieee 802.11p: Towards aninternational standard for wireless access in vehicular environments,” in VTCSpring 2008 - IEEE Vehicular Technology Conference. Marina Bay, Singapore:IEEE, May 2008, pp. 2036–2040.
[0011] [3] Y. Liang, H. Yan, and Y. Liu, “Unlinkable signcryption scheme formultireceiver in vanets,” IEEE Transactions on Intelligent TransportationSystems, vol. 24, no. 9, pp. 10 138–10 154, 2023.
[0012] [4] Y.-H. Hung, S.-S. Huang, Y.-M. Tseng, and T.-T. Tsai, “Efficient anonymous multireceiver certificateless encryption,” IEEE Systems Journal, vol. 11, no. 4, pp. 2602–2613, 2017.
[0013] [5] L. Deng, “Anonymous certificateless multi-receiver encryption scheme for smart community management systems,” Soft Computing, vol. 24, pp. 281–292, 2019.
[0014] [6] L. Li, D. Chen, Y. Liu, Y. Liang, Y. Wang, and X. Wu, “Unlinkable and revocable signcryption scheme for vanets,” Electronics, vol. 13, no. 16, 2024.
[0015] [7] Y. Qu and J. Zeng, “Anonymous certificateless multireceiver encryption scheme for mobile communication devices,” IEEE Systems Journal, vol. 17, no. 1, pp. 314–324, 2023.
[0016] [8] T. Alladi, V. Chamola, N. Naren, and N. Kumar, “Parth: A two stage lightweight mutual authentication protocol for uav surveillance networks,” Computer Communications, vol. 160, pp. 81–90, 2020. SUMMARY
[0018] The present application aims to overcome the deficiencies of the prior art, and provides a physically secure multi-receiver authentication method. The present application combines the Chinese remainder theorem with the idea of certificateless cryptography to design an authentication method with revocation function. In the present application, all legitimate terminals can decrypt the specific secret message sent by the sender, and the receiver does not need to be specified in advance. In addition, the present application integrates a physically unclonable function (PUF) and a fuzzy extraction technology, so that the key does not need to be stored continuously. This method essentially prevents unauthorized parties from extracting the key, thereby enhancing the security of the system.
[0019] To achieve the above object, the technical scheme of the present application is:
[0020] In a first aspect, the present application provides a physically secure multi-receiver authentication method, and the entities of the system include:
[0021] The certification authority CA is responsible for generating system parameters, managing the entire Internet of Vehicles system, and tracking and revoking malicious vehicles in the system.
[0022] The roadside unit RSU is responsible for verifying the validity of the received message. The message is processed locally or forwarded to the traffic control center.
[0023] Each vehicle is equipped with an on-board unit OBU, which is responsible for communicating with other vehicles, roadside units RSU and certification authorities CA. At the same time, the OBU is responsible for storing vehicle information and performing encryption operations on messages that need to be sent. A physically unclonable function PUF chip is installed in the OBU to prevent physical attacks.
[0024] In a second aspect, the present application provides a physically secure multi-receiver authentication method based on the above system, and the method includes:
[0025] Step 1. The certification authority CA initializes the system and discloses the public parameters and obtains the system master key;
[0026] Step 2. The vehicle initiates a registration request, and the vehicle obtains its real identity and revocation key from the CA;
[0027] Step 3. The vehicle obtains the public key, challenge value, response value and an auxiliary value;
[0028] Step 4. The CA generates a pseudonym and part of the public and private keys for the vehicle and sends them to the vehicle;
[0029] Step 5. The vehicle generates a verification value ver and an association table assoTab;
[0030] Step 6. The CA executes a revocation key generation algorithm for the n revoked keys corresponding to the n legitimate vehicles, and the CA obtains a master revocation key and an auxiliary value batVal;
[0031] Step 7. The vehicle executes a signature operation, and outputs the ciphertext corresponding to the plaintext, the signature of the vehicle on the message and a random point on the elliptic curve;
[0032] Step 8. The signature is verified, which is divided into single signature verification and batch signature verification, the single signature verification executes Step 8.1, and the batch signature verification executes Step 8.2;
[0033] Step 8.1. The vehicle executes a single signature verification operation, and outputs the plaintext or (indicating that the verification fails);
[0034] Step 8.2. The vehicle executes a batch signature verification operation, and outputs a group of plaintexts or ;
[0035] Step 9. The CA updates the pseudonym and part of the public and private keys for the vehicle.
[0036] Compared with the prior art, the present application has the beneficial effects that:
[0037] (1) By combining the Chinese remainder theorem with certificateless cryptography, a comprehensive multi-recipient authentication method is proposed. In the present application, all legitimate terminals can decrypt the given encrypted message without the sender specifying the recipient in advance, which significantly improves the flexibility of multi-recipient authentication.
[0038] (2) The present application incorporates anonymity and revocation mechanisms. Once a malicious vehicle is identified, the certification authority (CA) can track its real identity and remove it from the system. All revocation operations are concentrated in the CA, avoiding additional computational costs for resource-constrained terminals (vehicles or roadside units (RSUs)). Moreover, the time complexity of the revocation operation at the CA can be controlled at a constant level, greatly improving the revocation efficiency.
[0039] (3) To prevent the key from being obtained by the attacker through physical means, the present application uses the challenge-response pair mechanism of the physically unclonable function (PUF), and the vehicle can generate a private key on demand for signature, rather than storing the private key in the tamper-proof device (TPD) for a long time. This avoids the private key being obtained by the attacker, ensuring the physical security of the system. BRIEF DESCRIPTION OF DRAWINGS
[0041] Figure 1 is a system model diagram;
[0042] Figure 2The technical scheme of the present application is further described below in combination with the drawings and examples. DETAILED DESCRIPTION
[0044] Embodiment:
[0045] The technical scheme of the present application is further described below in combination with the drawings and examples.
[0046] Reference Figure 1 As shown in the figure, the system composition of the physically secure VANET multi-receiver authentication scheme provided by the embodiment involves entities mainly including: a certification authority (CA), a road side unit (RSU) and a vehicle. In order to reduce the communication delay between the vehicle and the certification authority and improve the security and stability, it is assumed that there are multiple certification authorities in the vehicle ad hoc network. These certification authorities can be managed in layers, and each certification authority only covers a smaller geographic area to provide services for a limited number of vehicles.
[0047] The certification authority (CA) is assumed to be the only fully trusted entity with strong computing and storage capabilities. It is responsible for generating system parameters, managing the entire vehicle ad hoc network, and tracking and revoking the real identity of any vehicle with malicious behavior. The road side unit is deployed on the roadside. The vehicle and the road side unit communicate through a wireless channel, while the road side unit and the certification authority communicate through a stable wired channel. In addition, the road side unit can verify the validity of the received message. If the message is valid, the road side unit will send it to the traffic control center or process the received message locally. Finally, it should be noted that the road side unit is not a fully trusted entity. The vehicle is equipped with an on-board unit (OBU) responsible for communicating with other vehicles, road side units and certification authorities. The on-board unit (OBU) stores the vehicle's information and performs encryption operations. At the same time, a physically unclonable function (PUF) chip is installed in the on-board unit to resist physical attacks. However, the vehicle is also not a fully trusted entity.
[0048] The physically secure VANET multi-receiver authentication method provided by the embodiment mainly includes the following steps as shown in the figure. Figure 2
[0049] Step 1. The certification authority CA initializes the system and discloses the public parameters and obtains the system master key;
[0050] Step 2. The vehicle initiates a registration request, and the vehicle obtains its real identity and revocation key from the CA;
[0051] Step 3. The vehicle obtains the public key, challenge value, response value and an auxiliary value;
[0052] Step 4. CA generates pseudonym and partial public-private key for vehicle and sends it to vehicle;
[0053] Step 5. Vehicle generates verification value ver and association table assoTab;
[0054] Step 6. CA executes revocation key generation algorithm for n vehicles corresponding to revoked key, CA obtains master revocation key and an auxiliary value batVal;
[0055] Step 7. Vehicle executes signature operation, outputs ciphertext corresponding to plaintext, vehicle's signature on the message and a random point on elliptic curve;
[0056] Step 8. Verify signature, divided into single signature verification and batch signature verification, single signature verification executes Step 8.1, batch signature verification executes Step 8.2;
[0057] Step 8.1. Vehicle executes single signature verification operation, outputs plaintext or (indicates verification failure);
[0058] Step 8.2. Vehicle executes batch signature verification operation, outputs a set of plaintexts or ;
[0059] Step 9. CA updates pseudonym and partial public-private key for vehicle.
[0060] In a specific embodiment, the above-mentioned step Step 1 initialization includes the following operations:
[0061] We set the security parameter as the basic security measure, which guides the bit length of all cryptographic primitives. The certificate authority (CA) executes this system initialization algorithm.
[0062] (1) CA selects two large prime numbers , of length 258 bits, selects a finite field of modulus , selects a non-singular elliptic curve , where . Then, the CA selects a group of order and generator from .
[0063] (2) CA selects as the system private key and calculates the system public key .
[0064] (3) CA selects a hash function 、 、 、 、 、 、 、 and where denotes the length of real identity or pseudonym, denotes the length of message to be transmitted, denotes the timestamp.
[0065] (4) CA generates a pool of prime numbers , containing 5 million unique 128-bit random large prime numbers. Its elements will gradually be depleted in the algorithm execution; when it is about to be depleted, the system generates new random large prime numbers to supplement.
[0066] (5) CA publishes system parameters to all RSUs and vehicles.
[0067] Note: To ensure the simplicity of the algorithm input, the subsequent steps are defaulted to use params as input.
[0068] In a specific embodiment, the above-mentioned step Step 2 vehicle registration includes the following operations:
[0069] CA selects a real identity for the registered vehicle, then selects a prime number from the pool of prime numbers , removes from , and finally sends to the registered vehicle through a secure channel.
[0070] In a specific embodiment, the above-mentioned step Step 3 vehicle key generation includes the following operations:
[0071] (1) Vehicle generates an initial challenge-response pair through a PUF chip, where .
[0072] (2) Adjust the value of through a fuzzy extraction function (FE), that is, calculate .
[0073] (3) Vehicle calculates its private key and public key .
[0074] (4) Vehicle computation By encrypting the revocation key of the vehicle through this operation, it is impossible for any other entity to obtain the revocation key of the vehicle.
[0075] (5) Vehicle publishes its public key , while only securely storing , , and . The private key and the revocation key are immediately deleted. The above measures have two purposes: to prevent and leakage, and to resist physical attacks.
[0076] In a specific embodiment, the above step Step 4, in which the vehicle generates a pseudonym and a partial public-private key pair, includes the following operations:
[0077] (1) The CA checks whether the real identity of the vehicle is valid. If valid, the CA performs the subsequent process; otherwise, the CA returns .
[0078] (2) The CA randomly selects a number , calculates , . Thus, the CA obtains the pseudonym .
[0079] (3) The CA randomly selects a number , calculates , and . In this way, the CA obtains the partial public-private key pair .
[0080] (4) The CA sends to the vehicle that initiates the request through a secure channel , and publishes the public key .
[0081] In a specific embodiment, the above step Step 5, in which the vehicle saves the secure information, includes the following operations:
[0082] (1) For the vehicle with the pseudonym , the verification value is obtained by calculating , and then the data element is securely stored and is discarded. We can provide higher degrees of physical security assurance for such information through these steps.
[0083] (2) To prevent replay attacks, the vehicle establishes an association table , whose structure is (pseudonym, timestamp) pair.
[0084] In one embodiment, the above-mentioned step Step 6 of assigning a revocation key to a legal vehicle includes the following process:
[0085] (1) The CA selects a random binary integer c with bit length less than 128 (much smaller than any element in as the master revocation key.
[0086] (2) The CA uses the Chinese Remainder Theorem (CRT) to construct the auxiliary value. First, the CA calculates , and then determines the multiplicative inverse of modulo , satisfying . Since are different prime numbers, and are coprime, ensuring the existence of the multiplicative inverse modulo . Next, the CA calculates the auxiliary value .
[0087] (3) The CA secretly saves the master revocation key c and publishes batVal, where the auxiliary value is a large integer.
[0088] Remark 1: After the CA updates batVal, it first sends batVal to each roadside unit (RSU) through wired communication. Then, each RSU sends the latest batVal to the vehicles within its coverage domain. In this way, the updated batVal can be quickly delivered to each vehicle.
[0089] Remark 2: To enhance the security of the entire system, c needs to be updated regularly. Therefore, this method is executed every two weeks. After each update, the intermediate variables and the latest batVal value need to be saved. Among them, and the corresponding vehicle identity will be stored in the form of a tuple ( ).
[0090] In one embodiment, the above-mentioned step Step 7 of sending the vehicle signature includes the following operations:
[0091] (1) The vehicle uses its PUF chip to generate a challenge-response pair again where Then, using the blinding extraction function FE, by computing we get Once the vehicle is subjected to a physical attack, the new response value will be the same as the original .
[0092] (2) Subsequently, the vehicle performs a verification process to check whether it is subjected to a physical attack: it computes and then checks whether holds. If it does, it means that the vehicle is not subjected to a physical attack; if it does not, it means that a physical attack is detected and the vehicle will prematurely terminate the subsequent sending operation and take remedial measures, such as re-registration and re-generation of the password.
[0093] (3) The vehicle's revocation key is recovered by computing .
[0094] (4) The vehicle uses the operation to obtain the master revocation key set by the CA, noting that "mod" is the modulo operation, and then immediately deletes .
[0095] Note: At the receiving end, a legitimate vehicle can obtain the same revocation key in the same way. However, an illegitimate receiving party will not be able to obtain the correct due to the lack of a legitimate revocation key .
[0096] (5) The vehicle computes its private key .
[0097] (6) Suppose the vehicle needs to send a message to surrounding vehicles, the vehicle selects a random number , computes , , , and then computes the vehicle's signature for the message : where is the timestamp.
[0098] (7) The vehicle obtains the session key: and uses as Key to encrypt the message , i.e. , then immediately delete . Note that the length of the ciphertext after AES encryption is the same as the length of the plaintext. Next, the vehicle broadcasts the message to nearby Roadside Units (RSUs) and vehicles.
[0099] In a specific embodiment, the above-mentioned step Step 8 is divided into single signature verification and batch signature verification.
[0100] Single signature verification includes the following operations:
[0101] (1) The vehicle checks the validity of the timestamp . If valid, it continues to perform the next verification operation; otherwise, the vehicle rejects the message and returns .
[0102] (2) The vehicle checks whether there is a tuple in the association table . If there is, it means a replay attack has occurred, and the subsequent operation will be abandoned, returning ; if not, it continues to perform the following operations.
[0103] (3) The vehicle generates a challenge-response pair again through the PUF chip , where . Then it obtains by calculating .
[0104] (4) Subsequently, the vehicle calculates , then checks whether holds. If it does, it means that no physical attack has been suffered; otherwise, a physical attack is detected, and the vehicle terminates the subsequent verification operation.
[0105] (5) The revoked key is recovered by .
[0106] (6) The vehicle obtains the revoked master key (this is equivalent to the key selected by the CA, and the proof process is shown in equation (1)) through , then immediately deletes .
[0107] (7) Calculate and use the key to decrypt the ciphertext as the decryption algorithm of AES : . Then delete and .
[0108] (8) The vehicle can quickly obtain (9) In the association table ( because , and are stored in the same tuple), calculate , , , and then verify the validity of the signature by checking whether this equation holds. If it does, the vehicle accepts the message ; otherwise, the vehicle rejects the message .
[0109] (9) In the association table , store the tuple , and clear those very old records.
[0110] Note: Since it is a legal vehicle, there is no need to specify in advance at the sending end to correctly receive information from legal vehicles, greatly improving the efficiency of broadcast communication.
[0111] Batch signature verification includes the following operations:
[0112] (1) After the vehicle receives messages from different vehicles, it checks the validity of all time stamps ( the number of received messages ). If all time stamps are valid, go to the next step; otherwise, the vehicle rejects the message with invalid time stamp.
[0113] (2) Check if the association table exists pair. If not, go to the next step; if exists, discard the corresponding message and return (verification failed), re-execute the algorithm.
[0114] (3) The vehicle randomly selects a set of random numbers , where is a small random integer.
[0115] (4) The vehicle The revocation key is obtained by the method of Step 8 , and then the master revocation key is obtained , and the revocation key is immediately deleted . Then, the ciphertext is decrypted using the AES algorithm and the decryption key : , and the decrypted plaintext is immediately deleted and .
[0116] (5) The vehicle calculates , , , and checks whether formula (1) is satisfied. If satisfied, all messages are accepted; otherwise, they are rejected.
[0117]
[0118] (1)
[0119] (6) Finally, the is stored in the , and the expired records are cleared.
[0120] In a specific embodiment, the above-mentioned Step 9, when the vehicle updates the pseudonym and part of the public and private keys, includes the following operations:
[0121] (1) The vehicle first calculates , where is the time stamp. Then, the vehicle sends the information to the CA.
[0122] (2) After receiving , the CA first verifies the validity of the time stamp . If valid, the corresponding real identity of the vehicle is retrieved from the database according to , the is calculated, and the is checked. If satisfied, it is confirmed that the request is legal and valid.
[0123] (3) The CA randomly selects a random number , calculates , . Thus, the CA obtains a new pseudonym about the vehicle .
[0124] (4) The CA randomly selects a random number ,calculate , as well as Therefore, the CA obtains a new partial public-private key pair. .
[0125] (5) The CA uses the AES algorithm to encrypt the private key. ,in It's a timestamp.
[0126] (6) CA calculates the verification value Then, the CA transmits the information through a public channel. Send to the requesting vehicle .
[0127] (7) Vehicle received Next, verify the timestamp. The validity. If valid, according to Retrieve from database ,calculate and check Is this condition met? If so, the vehicle uses the formula. Decrypt private key and use new information Replace old information .
Claims
1. A physically secure vehicular ad hoc network multi-recipient authentication scheme, characterized in that: The system includes the following three types of entities: Certificate Authority (CA): responsible for generating system parameters, managing the entire vehicular ad hoc network system, tracking and revoking malicious vehicles in the system; Roadside unit (RSU): responsible for verifying the validity of received messages, processing or forwarding messages locally to the traffic control center; Vehicle: each vehicle is equipped with an on-board unit (OBU), which is responsible for storing vehicle information and performing encryption operations on messages that need to be sent, and a physically unclonable function (PUF) chip is installed in the OBU to prevent physical attacks; The method comprises: Step 1. The Certificate Authority CA initializes the system and discloses the public parameters and obtains the system master key; Step 2. The vehicle initiates a registration request, and the vehicle obtains its true identity and revocation key from the CA; Step 3. The vehicle obtains a public key, a challenge value, a response value, and an auxiliary value; Step 4. The Certificate Authority CA generates a pseudonym and partial public and private keys for the vehicle and sends them to the vehicle; Step 5. The vehicle generates a verification value ver and an association table assoTab; Step 6. For the revocation keys corresponding to n legal vehicles, the CA performs a revocation key generation algorithm, and the CA obtains a master revocation key and an auxiliary value batVal; Step 7. The vehicle performs a signature operation, outputs the ciphertext corresponding to the plaintext, the vehicle's signature on the message, and a random point on an elliptic curve; Step 8. Verify the signature, which is divided into single signature verification and batch signature verification, single signature verification executes Step 8.1, and batch signature verification executes Step 8.2; Step 8.
1. The vehicle performs a single signature verification operation, outputting either plaintext or (representing a verification failure); Step 8.
2. The vehicle performs the batch signature verification operation, outputting a set of plaintexts or ; Step 9. The CA updates the pseudonym and partial public and private keys for the vehicle.
2. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, The Step 1 comprises: (1) CA selects two large prime numbers with a length of 258 bits. , Select Model finite field Choose a non-singular elliptic curve ,in Then, CA from Select an order of The generator is group ; (2) CA selection as the system private key, and compute the system public key , note that the ” is an elliptic curve scalar multiplication operation; (3) CA selects a hash function , , , , Note that the ” in this document is a multiplication operation between two real numbers, , , , and , where denotes the real identity or pseudonym length, denotes the length of the message to be transmitted, denotes the timestamp; (4) CA generates a pool of prime numbers containing approximately 5 million distinct 128-bit random large prime numbers; (5) The CA releases the system parameters to all RSUs and vehicles.
3. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, The Step 2 comprises: CA selects a real identity for the registered vehicle , then selects a prime number from a prime number pool , and sends it to the registered vehicle through a secure channel. 4. The physically secure vehicle-to-everything multi-recipient authentication scheme of claim 1, wherein, The Step 3 comprises: (1) Vehicle Generating an initial challenge-response pair by a PUF chip wherein ; (2) Adjusting via fuzzy extraction function (FE) The value, i.e., the calculation ; (3) vehicle computes its private key , public key ; (4) Vehicle computing ; (5) vehicle publishing its public key while securely storing , , and , the private key and the revocation key are deleted immediately.
5. The physically secure vehicle-to-everything multi-recipient authentication scheme of claim 1, wherein, The Step 4 comprises: (1) The CA checks whether the real identity of the vehicle is valid. If valid, the CA performs the subsequent process, otherwise, the CA returns ; (2) CA randomly selects a number , calculates , , and thus CA obtains a pseudonym ; (3) CA randomly selects a number , calculates , and , so that the CA obtains a partial public-private key pair ; (4) CA sends to the vehicle that initiated the request over a secure channel and discloses the public key .
6. The physically secure vehicle-to-everything multi-recipient authentication scheme of claim 1, wherein, The Step 5 comprises: (1) The vehicle with a pseudonym calculates a verification value, then stores the data elements securely and discards them; (2) To prevent replay attacks, the vehicle builds an association table whose structure is (pseudonym, timestamp) pairs.
7. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, The Step 6 comprises: (1) CA selects a random binary integer c, whose bit length is less than 128 bits (compared to...). (where any element is smaller) serves as the master revocation key; (2) First, the CA calculates , then determines the multiplicative inverse of , which satisfies Since are different prime numbers, and are coprime, it is ensured that the multiplicative inverse of exists, and next, the CA calculates the auxiliary value ; (3) The CA secretly keeps the master revocation key c and publicly discloses batVal.
8. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, The Step 7 comprises: (1) Vehicle Generating a challenge-response pair again with its PUF chip where Then using a fuzzy extraction function FE, by computing results in Once the vehicle is subjected to a physical attack, the new response value will be different from the original one; (2) Subsequently, the vehicle performs verification of whether a physical attack is suffered: calculation and then checks whether it is true or not to determine whether a physical attack is suffered; (3) The vehicle's revocation key is recovered by the equation ; (4) vehicle using obtaining the master revocation key set by the CA and then immediately deleting ; (5) vehicle computes its private key ; (6) Assuming vehicle Need to send message to surrounding vehicles , vehicle Select a random number Calculate , , , Where is a timestamp, is the signature of the vehicle for the message ; (7) vehicle The session key is obtained: and the message is encrypted using as the key of the algorithm i.e. and then immediately deleted Next, the vehicle broadcasts the message .
9. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, When verifying a single message, the Step 8.1 comprises the following operations: (1) by checking the validity of the time stamp to decide whether to proceed with the next operation; (2) vehicle check association table if there is a tuple , if there is, it means that a replay attack has occurred, the subsequent operation will be abandoned, return ; (3) vehicle Generating a challenge-response pair again through the PUF chip wherein then the fuzzy extraction function FE is made to obtain by calculating ; (4) Subsequently, the vehicle computes then checks whether this is true, and if not, a physical attack is detected, the vehicle terminates the subsequent verification operation; (5) by recovery revocation key ; (6) vehicle by revoked master key and then immediately deleted ; (7) Calculate and use the key as the decryption algorithm of AES to decrypt the ciphertext : and then delete and ; (8) Vehicles It is possible Get quickly ,calculate , , Then through inspection Whether this equation holds true thus verifies the signature. The validity of the vehicle, if valid, Receive message Otherwise the vehicle Rejection message ; (9) In the association table stores the tuple and clears the old record; When verifying a batch of messages, the Step 8.2 comprises the following operations: (1) Vehicles After receiving messages from different vehicles, check all timestamps. Validity ( (Number of messages received). If all timestamps are valid, proceed to the next step; otherwise, the vehicle... Reject messages containing invalid timestamps; (2) Check association table If not present, go to next step, if present, discard corresponding message and return Yes, if not present, go to next step, if present, discard corresponding message and return (Verification failed), re-execute algorithm; (3) vehicle a set of random numbers is randomly selected wherein is a small random integer; (4) vehicle Obtain revocation key by method of Step 8 , and then Obtain master revocation key , immediately delete , then calculate , using AES algorithm and decryption key Decrypt ciphertext : , immediately delete after decryption and ; (5) vehicle computing , , check if formula (1) holds, accept all messages if yes, otherwise reject; (1) (6) Finally, the stored expired records are cleared.
10. The physically secure V2X multi-recipient authentication scheme of claim 1, wherein, The Step 9 comprises: (1) Vehicles First calculate ,in It's a timestamp, and then the vehicle will send the information. Send to CA; (2) CA received Next, verify the timestamp. The validity of, if valid, according to Retrieve their real identity from the database. ,calculate and check If the request is valid, then it is confirmed that the request is legal and valid. (3) The CA randomly selects a random number , calculates , , and thereby the CA obtains a new pseudonym for the vehicle ; (4) CA randomly selects a random number , calculates , and Thus, the CA gets a new partial public-private key pair ; (5) CA uses AES algorithm to encrypt the private key wherein is a time stamp; (6) CA calculates verification value Then, the CA sends the information to the requesting vehicle over a public channel (7) Vehicle received Next, verify the timestamp. The validity of, if valid, according to Retrieve from database ,calculate and check If true, then the vehicle uses the formula. Decrypt private key and use new information Replace old information .