Certificateless signcryption method, system and device for resisting quantum attack in Internet of Vehicles

By employing a certificateless signature method and lattice cryptography algorithm, this approach solves the problems of traditional cryptography's vulnerability to quantum attacks and the complexity of certificate management in the Internet of Vehicles (IoV), achieving efficient communication security and vehicle behavior tracking, and is suitable for high-frequency data transmission between vehicles.

CN121508874APending Publication Date: 2026-02-10CHANGZHOU SMART CLOUD NETWORK INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511876555.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing vehicle networking systems, traditional cryptographic algorithms are vulnerable to quantum computing attacks, certificate management is complex and communication overhead is high, making them unsuitable for low-latency, highly dynamic vehicle networking environments and unable to effectively guarantee the confidentiality, integrity and verifiability of communication between vehicles.

Method used

It adopts a certificateless signature method, uses lattice cryptography to generate system parameters and private keys, combines signature and encryption operations, and achieves resistance to quantum attacks through a chain tag mechanism, simplifies key management, and supports high-frequency communication data protection.

Benefits of technology

It achieves resistance to quantum attacks, reduces computational and communication load, ensures user autonomy over private keys, supports vehicle behavior correlation analysis and security event tracing, and guarantees communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508874A_ABST
    Figure CN121508874A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum attack certificateless signcryption method, system and device in the Internet of Vehicles, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: generating a system public parameter, a main public key and a main private key through a system parameter and a security parameter preset by a vehicle Internet of Vehicles system by a key generation center; obtaining a partial private key based on the identity identifier of the sender, and combining the partial private key with a locally generated random vector to obtain a complete private key of the sender; the sender vehicle performs signcryption operation on the plaintext message by using the complete private key of the sender vehicle and the public key of the receiver, and generates a signcryption text containing a ciphertext and a link label; the receiver carries out decryption and signature verification on the received signcryption text by using a private key of the receiver; according to the method, the lattice cryptographic algorithm based on the error learning and short integer solution problem is introduced, so that the capability of resisting quantum attacks is realized, and the security requirement of the Internet of Vehicles for resisting quantum computing threats in the future is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle network information security technology, specifically to a certificateless signature method, system, and device for resisting quantum attacks in vehicle networks. Background Technology

[0002] With the development of communication technology, mobile networks and the automotive industry, as well as automobiles, are no longer just simple means of transportation. Vehicles equipped with intelligent devices such as wireless sensors, onboard computers, GPS antennas, and radar can collect and process large amounts of data, while also enabling information exchange between vehicles. The widespread adoption of intelligent connected vehicles has made vehicle-to-everything (V2X) a core infrastructure of intelligent transportation systems. High-frequency communication between vehicles, between vehicles and roadside equipment, and between vehicles and the cloud requires ensuring data confidentiality, integrity, and verifiability in a complex, high-speed mobile network environment.

[0003] Currently, many encryption and authentication schemes exist in vehicle-to-everything (V2X) and VANET systems, but they typically rely on traditional cryptographic algorithms, such as those based on discrete logarithms and large integer factorization. These algorithms are vulnerable to quantum computer attacks. While some quantum-resistant authentication key protocol solutions exist, in V2X systems, information such as traffic flow, speed, and accident details change over time, making it difficult to address privacy requirements. Although traditional certificate-based public key interoperability (PKI) systems offer high security, their complex certificate management and high communication overhead make them unsuitable for low-latency, highly dynamic V2X environments. Furthermore, they cannot determine whether different messages originate from the same sender, and certificate management is complex and storage overhead is high. Summary of the Invention

[0004] To address the shortcomings of existing technologies, such as complex certificate management and high communication overhead, which make them unsuitable for low-latency, high-dynamic vehicle-to-everything (V2X) environments, this invention proposes a certificate-free signature encryption method, system, and device for V2X that is resistant to quantum attacks. By integrating signature and encryption operations, it avoids certificate management, possesses quantum resistance capabilities, and ensures the associativity of user messages. It is suitable for high-frequency communication data protection between vehicles and between vehicles and infrastructure, thereby solving the problems existing in the prior art.

[0005] A certificate-free signature method for quantum-resistant Internet of Vehicles (IoV) systems involves a key generation center generating system public parameters, a master public key, and a master private key using lattice cryptography algorithms based on preset system and security parameters of the IoV system. The method includes the following steps: Obtain a partial private key based on the sender's identity identifier; the partial private key is generated by the key generation center based on the sender's identity identifier and the system's master public key and master private key; the sender generates a random vector locally and combines it with the partial private key to obtain the sender's complete private key; The sending vehicle uses its own complete private key and the receiving vehicle's public key to perform a sign-crypto operation on the plaintext message, generating a signed ciphertext containing ciphertext and a link tag, and then sends it to the receiving vehicle; the link tag is generated based on the sender's partial private key, master public key, and random vector. The recipient uses its own private key to decrypt and sign the received ciphertext. At the same time, the recipient determines the anonymity association of multiple messages from the same sender based on the link tags.

[0006] Furthermore, the step of generating system public parameters, a master public key, and a master private key through the preset system parameters and security parameters of the vehicle network system specifically includes the following steps: Preset system parameters in the vehicle networking system and safety parameters ; According to system parameters and safety parameters The key generation center selects a prime number. Generate public parameters and master public key and the master private key The key generation center generates a lattice matrix using the TrapGen algorithm. and its lattice basis matrix Sampling parameters The public parameters include two hash functions. and lattice matrix lattice basis matrix Grid sampling parameters Discrete Gaussian distribution and safety parameters ; the master key Designated as Master private key Designated as The two hash functions and Represented as: ; ; in, This indicates that the input can be of any length. express A finite field of elements .

[0007] Furthermore, obtaining a portion of the private key based on the sender's identity identifier specifically includes the following steps: In a vehicle-to-everything (V2X) system, each onboard unit registers its identity with a key generation center upon initial access to the system. ; Their identity is calculated through the key generation center. hash value ; According to the lattice matrix lattice basis matrix Grid sampling parameters and hash value The SamplePre function calculates a partial key based on the user's identity. .

[0008] Furthermore, the sending vehicle uses its full private key and the receiving party's public key to perform a sign-crypto operation on the plaintext message, generating a signed ciphertext containing ciphertext and a link tag, and then sends it to the receiving party. This specifically includes the following steps: The sending vehicle uses its own complete private key. and random vectors Generate link tags ; Sender vehicle calculates ciphertext ;in, ; ; ; It is a signature generated by the sender based on its identity. All are vectors randomly selected by the sender; m This indicates a plaintext message; and The random matrix and vector chosen when generating the public key for the recipient. and For the identification of the sender and receiver, It is part of the recipient's public key; According to the cipher and tags Generate a signed message and send it to the recipient. .

[0009] Furthermore, the recipient uses its own private key to decrypt and verify the received ciphertext, and the decryption process is represented as follows: ; in For ciphertext Content; and The two parts are the recipient's private key; Its signature verification process is represented as follows: ; in, A vector randomly selected by the sender; and The random matrix chosen when generating the public key for the sender and receiver and Identification of the sender and receiver If the equation is true, the signature is correct, and the decrypted ciphertext is obtained. Otherwise, the application will be rejected.

[0010] This invention also includes a certificateless signature encryption system resistant to quantum attacks in the Internet of Vehicles (IoV). Based on the system parameters and security parameters preset in the IoV system, a key generation center generates system public parameters, a master public key, and a master private key, including: The acquisition module is used to acquire a partial private key based on the sender's identity identifier; the partial private key is generated by the key generation center based on the sender's identity identifier and the system's master public key and master private key; the sender generates a random vector locally and combines it with the partial private key to obtain the sender's complete private key; The signature module is used by the sending vehicle to perform signature operations on the plaintext message using its own complete private key and the receiving party's public key, generating a signature message containing ciphertext and a link tag and sending it to the receiving party; the link tag is generated based on the sender's partial private key, master public key, and random vector; The decryption and verification module is used by the receiver to decrypt and sign the received ciphertext using their own private key. At the same time, the receiver determines the anonymity association of multiple messages from the same sender based on the link tags.

[0011] The present invention also includes a certificateless signature computer device resistant to quantum attacks in a vehicle network, comprising: a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the certificateless signature method resistant to quantum attacks in a vehicle network.

[0012] The present invention also includes a readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, are used to perform the steps of the certificateless signature method for resisting quantum attacks in the Internet of Vehicles.

[0013] This invention provides a certificateless signature method for resisting quantum attacks in the Internet of Vehicles (IoV), which has the following beneficial effects: This invention introduces a lattice cryptography algorithm based on error learning and the short integer solution problem, achieving resistance to quantum attacks and meeting the security requirements of future vehicle-to-everything (V2X) networks against quantum computing threats. It employs signature cryptography, completing two independent cryptographic operations—digital signature and public-key encryption—in a single computation. Compared to traditional "sign first, then encrypt" or "encrypt first, then sign" schemes, this significantly reduces computational overhead and communication load. By introducing a user-selected secret value, it effectively solves the key escrow problem, ensuring complete autonomy over the user's private key. It innovatively introduces a link tag mechanism. This mechanism allows authorized recipients (such as traffic management centers and roadside equipment) to compare the link tags attached to different ciphertexts to determine if they originate from the same vehicle, thereby enabling correlation analysis of vehicle behavior and tracing of security events. This method is suitable for high-frequency, sensitive data transmission between vehicle terminals, roadside equipment, and cloud platforms, simultaneously achieving data encryption and signature operations, ensuring the confidentiality, integrity, and security of communication and identity authentication. Attached Figure Description

[0014] Figure 1 This is a flowchart illustrating a certificate-free signature method for resisting quantum attacks in a vehicle-to-everything (V2X) network, as described in this invention. Detailed Implementation

[0015] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0016] This invention proposes a certificate-free signature encryption method for quantum-resistant connected vehicles (V2V) networks. This method is suitable for high-frequency, sensitive data transmission between vehicle terminals, roadside equipment, and cloud platforms. It can simultaneously perform data encryption and signing operations, ensuring the confidentiality, integrity, and authentication security of communication. Compared to traditional certificate-based public key systems, this method adopts a certificate-free structure, effectively simplifying the key management process and avoiding key escrow issues. By introducing a lattice cryptography algorithm based on error learning and short integer solution problems, it achieves resistance to quantum attacks, meeting the security requirements of future V2V networks against quantum computing threats. The designed linking tag mechanism can be used to determine whether multiple ciphertexts originate from the same vehicle, realizing the correlation verification of vehicle behavior, which is helpful for secure tracking and traffic origination.

[0017] like Figure 1 As shown, the method specifically includes the following steps: S1. The key generation center generates a lattice base, sets the system public parameters, and generates a master public-private key pair.

[0018] Pre-enter system parameters in the vehicle network and safety parameters Subsequently, the key generation center based on parameters In addition to the requirements for security and performance, a large prime number is randomly selected. Generate public parameters and master / public key pairs. and The key generation center selects two hash functions:

[0019] Then the key generation center generates a lattice matrix using the TrapGen algorithm. , its basis matrix Passing sampling parameters k

[0020] The public parameters include two hash functions. and lattice matrix lattice basis matrix Grid sampling parameters Discrete Gaussian distribution and safety parameters The master public key Designated as Master private key Designated as .

[0021] S2. The vehicle node generates a partial private key based on its identity identifier through the key generation center, and combines it with its own randomly selected private value to generate a complete private key and a public key.

[0022] In a connected vehicle environment, each onboard unit registers its identity through a key generation center when it first connects to the system. Then the key generation center calculates its hash value. Using lattice matrices lattice basis matrix Grid sampling parameters and hash value The partial key based on its identity is calculated using the SamplePre function. The private key is then transmitted to the vehicle unit via a secure private channel.

[0023] The vehicle then generates a random matrix locally. vector Random vector and Combine to form a complete private key The public key is then calculated using the following formula. :

[0024] in, These are random values ​​that follow a discrete Gaussian distribution. The vehicle then broadcasts the public parameters and public key to the roadside unit or the cloud.

[0025] S3. The sending vehicle uses its private key and the receiving vehicle's public key to perform a signature encryption algorithm on the information to be transmitted, generate ciphertext and a link tag, and send it to the receiving vehicle.

[0026] Specifically, in the communication process between vehicles or between a vehicle and a roadside unit, the sending vehicle To transmit plaintext traffic messages containing location, speed, status, etc. m Passed to the recipient First, the vehicle performs a signature operation using its own private key. and random vectors Generate link tags The following formula was used:

[0027] Then the sending vehicle calculates the ciphertext. and ciphertext and tags The following formula was used to send the message to the receiving vehicle: in It is the sender based on The generated signature, Both are vectors randomly selected by the sender.

[0028] S4. The recipient uses its own private key to decrypt the ciphertext and verify the correctness of the signature; The recipient received the encrypted message Then, use your own private key Complete decryption, and use the encryptor's public key. The following decryption formula was used to verify the integrity and authenticity of the message: ; in For ciphertext The content. Calculate the ciphertext. The signature's correctness was then verified using the following formula to check if the hash values ​​matched:

[0029] If the above equation holds true, the signature is correct, and the decrypted ciphertext is obtained. If the signature is incorrect, it indicates an error message, and the message is rejected.

[0030] S5. The receiver compares the link tags of multiple encrypted messages. If the tags match, it can be determined that the message comes from the same vehicle, thus enabling vehicle behavior tracking without exposing its identity.

[0031] If the recipient receives multiple related encrypted messages First, check if both ciphertexts are valid. If both are valid, then use the link tag. Perform a comparison, if This confirms that the message came from the same vehicle.

[0032] This invention ensures quantum-resistant security by constructing a solution with error learning and short integer solutions in lattice cryptography theory. It integrates signature and encryption, improving communication efficiency and achieving efficient communication authentication and data encryption resistant to quantum attacks. Furthermore, it uses a linked tag mechanism to support source identity consistency judgment for multiple vehicle messages, enabling vehicle behavior tracking without exposing its identity, thus improving the manageability and secure traceability of traffic data. At the same time, it eliminates the certificate architecture in traditional solutions, avoiding certificate management and effectively circumventing the complexity of PKI management and the key custody problem of IB-PKC, thereby improving the system's practicality and security.

[0033] Based on the same inventive concept, this invention also proposes a certificateless signature encryption system resistant to quantum attacks in the Internet of Vehicles (IoV). Using the system parameters and security parameters preset in the IoV system, a key generation center generates system public parameters, a master public key, and a master private key using a lattice cryptography algorithm, including: The acquisition module is used to obtain a partial private key based on the sender's identity identifier. The partial private key is generated by the key generation center based on the sender's identity identifier and the system's master public key and master private key. The sender generates a random vector locally and combines it with the partial private key to obtain the sender's complete private key.

[0034] The signature module is used by the sending vehicle to perform signature operations on the plaintext message using its own complete private key and the receiving party's public key, generating a signature message containing ciphertext and a link tag and sending it to the receiving party; the link tag is generated based on part of the sending party's private key, master public key, and random vector.

[0035] The decryption and verification module is used by the receiver to decrypt and sign the received ciphertext using their own private key. At the same time, the receiver determines the anonymity association of multiple messages from the same sender based on the link tags.

[0036] This invention also proposes a certificateless signature computer device resistant to quantum attacks in the Internet of Vehicles (IoV), comprising: a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of a certificateless signature method resistant to quantum attacks in the IoV.

[0037] The present invention also proposes a readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, are used to perform steps of a certificateless signature method for resisting quantum attacks in the Internet of Vehicles.

[0038] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A certificate-free signature method for quantum-resistant encryption in vehicle-to-everything (V2X) networks, characterized in that, Based on the system parameters and security parameters preset in the vehicle-to-everything (V2X) system, the key generation center generates system public parameters, a master public key, and a master private key using a lattice cryptographic algorithm. The certificateless signature method includes the following steps: Obtain a partial private key based on the sender's identity identifier; the partial private key is generated by the key generation center based on the sender's identity identifier and the system's master public key and master private key; the sender generates a random vector locally and combines it with the partial private key to obtain the sender's complete private key; The sending vehicle uses its own complete private key and the receiving vehicle's public key to perform a sign-crypto operation on the plaintext message, generating a signed ciphertext containing ciphertext and a link tag, and then sends it to the receiving vehicle; the link tag is generated based on the sender's partial private key, master public key, and random vector. The recipient uses its own private key to decrypt and sign the received ciphertext. At the same time, the recipient determines the anonymity association of multiple messages from the same sender based on the link tags.

2. The certificateless signature method for resisting quantum attacks in the Internet of Vehicles (IoV) according to claim 1, characterized in that, The process of generating system public parameters, a master public key, and a master private key through the preset system parameters and security parameters of the vehicle network system includes the following steps: Preset system parameters in the vehicle networking system and safety parameters ; According to system parameters and safety parameters The key generation center selects a prime number. Generate public parameters and master public key and the master private key The key generation center generates a lattice matrix using the TrapGen lattice cryptography algorithm. and its lattice basis matrix Sampling parameters The public parameters include two hash functions. and lattice matrix lattice basis matrix Grid sampling parameters Discrete Gaussian distribution and safety parameters ; the master key Designated as Master private key Designated as The two hash functions and Represented as: ; ; in, This indicates that the input can be of any length. express A finite field of elements .

3. The certificateless signature method for resisting quantum attacks in the Internet of Vehicles (IoV) according to claim 2, characterized in that, Obtaining a portion of the private key based on the sender's identity identifier specifically includes the following steps: In a vehicle-to-everything (V2X) system, each onboard unit registers its identity with a key generation center upon initial access to the system. ; Their identity is calculated through the key generation center. hash value ; According to the lattice matrix lattice basis matrix Grid sampling parameters and hash value The SamplePre function calculates a partial key based on the user's identity. .

4. The certificate-free signature method for resisting quantum attacks in the Internet of Vehicles according to claim 3, characterized in that, The sending vehicle uses its full private key and the receiving vehicle's public key to perform a sign-crypto operation on the plaintext message, generating a signed ciphertext containing ciphertext and a link tag, and then sends it to the receiving vehicle. This process includes the following steps: The sending vehicle uses its own complete private key. and random vectors Generate link tags ; Sender vehicle calculates ciphertext ;in, ; ; ; It is a signature generated by the sender based on its identity. All are vectors randomly selected by the sender; m This indicates a plaintext message; and The random matrix and vector chosen when generating the public key for the recipient. and For the identification of the sender and receiver, It is part of the recipient's public key; According to the cipher and tags Generate a signed message and send it to the recipient. .

5. A certificate-free signature method for resisting quantum attacks in a vehicle-to-everything (V2X) network according to claim 4, characterized in that, The recipient uses its own private key to decrypt and verify the received ciphertext. The decryption process is as follows: ; in For ciphertext Content; and The two parts are the recipient's private key; Its signature verification process is represented as follows: ; in, A vector randomly selected by the sender; and The random matrix chosen when generating the public key for the sender and receiver and This serves as the identifier for both the sender and receiver; if this equation holds true, the signature is correct, and the decrypted ciphertext is obtained. Otherwise, the application will be rejected.

6. A certificateless signature system resistant to quantum attacks in the Internet of Vehicles, characterized in that, Based on the system parameters and security parameters preset in the vehicle-to-everything (V2X) system, the key generation center generates system public parameters, a master public key, and a master private key using a lattice cryptographic algorithm, including: The acquisition module is used to acquire a partial private key based on the sender's identity identifier; the partial private key is generated by the key generation center based on the sender's identity identifier and the system's master public key and master private key; the sender generates a random vector locally and combines it with the partial private key to obtain the sender's complete private key; The signature module is used by the sending vehicle to perform signature operations on the plaintext message using its own complete private key and the receiving party's public key, generating a signature message containing ciphertext and a link tag and sending it to the receiving party; the link tag is generated based on the sender's partial private key, master public key, and random vector; The decryption and verification module is used by the receiver to decrypt and sign the received ciphertext using their own private key. At the same time, the receiver determines the anonymity association of multiple messages from the same sender based on the link tags.

7. A certificate-free, signature-free computer device resistant to quantum attacks in the Internet of Vehicles (IoV), characterized in that, include: A memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the certificateless signature method for quantum-resistant Internet of Vehicles as described in any one of claims 1-5.

8. A readable storage medium, characterized in that, The readable storage medium stores a computer program, which includes program instructions. When executed by a processor, the program instructions are used to perform the steps of the certificateless signature method for resisting quantum attacks in the Internet of Vehicles as described in any one of claims 1-5.