Internet of vehicles identity authentication method and system based on PUF (Physical Unclonable Function)

By using a PUF-based vehicle-to-everything (V2X) identity authentication method, the PUF response value and key are dynamically updated, which solves the security risks caused by the long-term invariance of keys during multiple vehicle authentications. This achieves efficient identity authentication and key negotiation, protects user privacy, and enhances system security.

CN121864302APending Publication Date: 2026-04-14SHIHEZI UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-10
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing technologies, the long-term key used by vehicles during multiple authentication processes remains unchanged, which allows attackers to obtain secret parameters through machine learning, thereby leaking user location privacy and behavioral habits, posing a security risk.

Method used

A vehicle-to-everything (V2X) identity authentication method based on PUF is adopted. By generating random numbers and pseudo-name factors, the PUF response value is dynamically updated. Combined with hash functions and XOR operations, bidirectional authentication and key negotiation between vehicles and roadside units are realized, avoiding frequent involvement of TAs.

Benefits of technology

It improves the protocol's resilience against novel modeling attacks, protects user privacy, reduces authentication latency and communication burden, and enhances security and system scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864302A_ABST
    Figure CN121864302A_ABST
Patent Text Reader

Abstract

The invention discloses a PUF (Physical Unclonable Function)-based Internet of Vehicles identity authentication method and system, and relates to the technical field of Internet of Vehicles identity authentication, the method comprises the following steps: a vehicle and an RSU respond to and restore key parameters by using a preset PUF, and the vehicle sends a request containing a pseudo identity, a first authentication code and a temporary public key to the RSU; the RSU verifies the legality of the identity of the vehicle by calculating and comparing the first authentication code, and after the verification is passed, the RSU generates a second authentication code and an updated pseudo name and sends the second authentication code and the updated pseudo name to the vehicle; the vehicle completes identity authentication of the RSU by verifying the second authentication code; according to the method, both parties generate a unified session key by mixing parameters generated in two authentication processes, including a first authentication code, a second authentication code, an updated pseudo name and a temporary identity key obtained through elliptic curve Diffie-Hellman exchange, and after authentication succeeds, the both parties can independently update local PUF related parameters, so that the authentication efficiency is improved. Forward security is achieved, and machine learning attacks are effectively resisted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle network identity authentication technology, specifically to a vehicle network identity authentication method and system based on PUF. Background Technology

[0002] As the core of intelligent transportation systems, the Internet of Vehicles (IoV) greatly improves road safety and traffic efficiency through real-time communication between vehicles and roadside facilities, other vehicles, and cloud services. However, the high-speed mobility of vehicles, the dynamic nature of network topology, and the limited resources of onboard units pose serious security and privacy challenges to IoV, especially in the identity authentication and key negotiation stages, which have become the cornerstone of ensuring the security and trustworthiness of the entire system.

[0003] Currently, V2G networks face challenges such as data privacy protection, resource constraints, vulnerability to eavesdropping during communication, and security issues with traditional authentication protocols. Some scholars have proposed a vehicle-to-everything (V2G) anonymous authentication protocol based on PUF (Physically Unclonable Function) to address security issues like identity spoofing and privacy leaks. Others have proposed using the PUF's response as a temporary key to encrypt communication messages, solving the challenge-response pair storage problem and successfully resisting man-in-the-middle attacks. Still others have proposed a PUF-based authentication scheme where the stimulus-response pair (CRP) is not explicitly stored, successfully resisting machine learning attacks. Finally, some scholars have proposed a PUF-based RFID security authentication protocol, addressing the system's vulnerability to physical attacks and other security vulnerabilities. The issue of cloning attacks has been addressed. Some scholars have proposed an RFID authentication protocol based on dual PUFs, which resists desynchronization and spoofing attacks. Others have proposed a physically secure and conditional VANET key protocol scheme that combines elliptic curve cryptography (ECC) and PUFs to achieve mutual authentication and key negotiation between vehicles and RSUs. Furthermore, it eliminates the need for a Trusted Authority (TA) during authentication and key negotiation. Still others have proposed a V2I (vehicle-to-infrastructure) and V2V (vehicle-to-vehicle) authentication scheme based on elliptic curve cryptography, with batch verification. RSUs can perform batch authentication of vehicles without a TA, improving system performance and reducing system overhead. This scheme combines PUFs with biometric keys to resist RSU capture attacks and Onboard Unit (OBU) intrusion attacks, but it does not consider key escrow freedom. Finally, some scholars have proposed an authentication protocol that allows registration on a TA without TA involvement. This protocol combines elliptic curve cryptography (ECC) and PUFs, utilizing PUFs to prevent physical extraction of secrets from vehicles and RSUs, achieving mutual authentication and key negotiation.

[0004] However, in existing schemes, the long-term key generated by the TA (Technical Detection) remains unchanged during multiple authentication processes for the same vehicle. Leakage of the TA allows attackers to obtain the corresponding secret parameters. Attackers can collect a large number of PUF (Promotion-Response Array) pairs in public channels, use machine learning techniques to train a mathematical model of the PUF, and thus impersonate legitimate devices, leading to the leakage of users' location privacy and behavioral habits, posing a security risk. Summary of the Invention

[0005] To address the issue that existing technologies use TA-generated long-term keys that remain unchanged during multiple authentication processes, leading to insufficient access to the corresponding secret parameters by attackers, this invention proposes a PUF-based vehicle network identity authentication method and system, thereby solving the problems existing in the prior art.

[0006] A PUF-based vehicle-to-everything (V2X) authentication method is applied to a V2X system, which includes a roadside unit (RSU), vehicles, and trusted institutions. The method includes the following steps: The vehicle generates a first random number and a first pseudonym factor; and reconstructs a first private key and a trusted institution key based on the response value generated by the Physically Unclonable Function (PUF) of the trusted institution stored in the vehicle; generates a first authentication code based on the first private key, the trusted institution key, a first temporary public key generated based on the first random number, a first pseudonym generated based on the trusted institution key and the first pseudonym factor, and the RSU's public key; the vehicle sends a first message to the RSU containing the first pseudonym, the first authentication code, and the first temporary public key; After receiving the first message, the RSU generates a second random number and a second pseudonym factor; it reconstructs the second private key and trusted authority key based on the PUF response value stored in the RSU to verify the validity of the first authentication code; after successful verification, it generates a second authentication code based on the temporary identity key calculated based on the first temporary public key and the second random number, the second pseudonym generated based on the first pseudonym and the second pseudonym factor, the first authentication code, and the shared secret of the first temporary public key and the second random number; the RSU sends a second message to the vehicle containing the second pseudonym, the second authentication code, and the second temporary public key generated based on the second random number. After receiving the second message, the vehicle restores the temporary identity key based on the shared secret of the second temporary public key and the first random number and verifies the validity of the second authentication code; after the verification is successful, the vehicle generates a session key based on the first authentication code, the verified second authentication code, the second pseudonym and the restored temporary identity key, and sends a third message to the RSU. Upon receiving the third message, the RSU generates the session key based on the first authentication code, the second authentication code, the second pseudonym, and the temporary identity key, and verifies the third message to complete the two-way authentication and key negotiation between the vehicle and the RSU.

[0007] Furthermore, the first authentication code The generation process is represented as: ; Where H() is the hash function, A timestamp generated for the vehicle. The first pseudonym for the vehicle. The response generated by a physically unclonable function of a trusted institution serves as the shared key. This serves as the identification identifier for the target roadside unit. The first private key of the vehicle Public key of roadside unit registration The shared secret for performing scalar multiplication operations on elliptic curves. For the vehicle, based on the first random number of this authentication The first temporary public key generated.

[0008] Furthermore, the roadside unit verifies the first authentication code. The validity of the authentication code is specifically determined by calculating its hash value. By judgment Is it equal to the received? Complete the first authentication code Validation of effectiveness; among which This indicates that the roadside unit uses the vehicle's registered public key. With one's own second private key The shared secret of the calculation, the result of which is related to the vehicle's calculation. equal.

[0009] Furthermore, the temporary identity key By the roadside unit Calculated and passed by vehicles The result is obtained by restoring the original value, where ⊕ represents the XOR operation.

[0010] Furthermore, the second authentication code The generation process is represented as: , Among them, the vehicle's second pseudonym , The timestamp generated for the roadside unit This is the shared secret between the first temporary public key and the second random number.

[0011] Furthermore, the verification of the validity of the second authentication code is specifically achieved through calculation. To verify the second authentication code, and by judging Is it equal to To complete the certification of the roadside unit.

[0012] Furthermore, the session key is generated independently by the vehicle and the roadside unit, and the set of input parameters on which the session key is generated is consistent; wherein, The session key generated by the vehicle for: ; The session key generated by the roadside unit for: ; in, = ,and = Thus making = .

[0013] Furthermore, it also includes updating parameters after the key negotiation is completed, including the following steps: The vehicle generates a new response value using the new PUF challenge value and updates its locally stored encryption parameters using the first random number and temporary identity key; The roadside unit generates a new response value using the new PUF challenge value and updates its locally stored encryption parameters using the second random number and temporary identity key.

[0014] This invention also includes a PUF-based vehicle-to-everything (V2X) identity authentication system, applied to a V2X system, the V2X system including a roadside unit (RSU), vehicles, and trusted institutions; the V2X identity authentication system includes: The first message generation module is used for the vehicle to generate a first random number and a first pseudonym factor; and to reconstruct the first private key and the trusted institution key based on the response value generated by the Physically Unclonable Function (PUF) of the trusted institution stored in the vehicle; to generate a first authentication code based on the first private key, the trusted institution key, the first temporary public key generated based on the first random number, the first pseudonym generated based on the trusted institution key and the first pseudonym factor, and the RSU's public key; and for the vehicle to send a first message to the RSU containing the first pseudonym, the first authentication code, and the first temporary public key. After receiving the first message, the RSU generates a second random number and a second pseudonym factor; it reconstructs the second private key and trusted authority key based on the PUF response value stored in the RSU to verify the validity of the first authentication code; after successful verification, it generates a second authentication code based on the temporary identity key calculated based on the first temporary public key and the second random number, the second pseudonym generated based on the first pseudonym and the second pseudonym factor, the first authentication code, and the shared secret of the first temporary public key and the second random number; the RSU sends a second message to the vehicle containing the second pseudonym, the second authentication code, and the second temporary public key generated based on the second random number. After receiving the second message, the vehicle restores the temporary identity key based on the shared secret of the second temporary public key and the first random number and verifies the validity of the second authentication code; after the verification is successful, the vehicle generates a session key based on the first authentication code, the verified second authentication code, the second pseudonym and the restored temporary identity key, and sends a third message to the RSU. Upon receiving the third message, the RSU generates the session key based on the first authentication code, the second authentication code, the second pseudonym, and the temporary identity key, and verifies the third message to complete the two-way authentication and key negotiation between the vehicle and the RSU.

[0015] This invention provides a vehicle network identity authentication method based on PUF, which has the following beneficial effects: This invention introduces a random number and parameter update mechanism to ensure that even for the same user in different sessions, the PUF responses transmitted over the public channel are obfuscated with different random numbers. Furthermore, the locally stored PUF stimulus response pairs are updated with relevant parameters after each authentication, preventing attackers from collecting fixed stimulus response pairs for effective machine learning modeling and significantly improving the protocol's resilience against novel modeling attacks. The use of dynamically generated pseudo-identities and temporary identity keys in communication, updated with each authentication, prevents attackers from directly obtaining the vehicle's true identity from network traffic and from associating communication behavior in different sessions with the same vehicle, effectively protecting user location privacy and behavioral habits. The proposed two-way authentication and key negotiation process does not require online participation from a trusted institution, avoiding frequent interactions with the TA, significantly reducing authentication latency and communication burden, and making it more suitable for high-speed, resource-constrained vehicle-to-everything (V2X) applications. After completing one authentication, vehicles and RSUs can independently update their respective PUF-related parameters without TA assistance. This not only enhances security (resistance to machine learning attacks) but also further reduces the burden on the TA, improving the overall system's scalability and efficiency. Attached Figure Description

[0016] Figure 1 This is a diagram of the vehicle networking system architecture in an embodiment of the present invention; Figure 2This is a reliability comparison chart of the SDL PUF and various PUFs with different noise levels. Figure 3 The left side of this embodiment is a schematic diagram of the PUF response values ​​when different users register, and the right side is a schematic diagram of the PUF response when the same user authenticates multiple times. Figure 4 This is a comparison chart of calculated costs in an embodiment of the present invention; Figure 5 This is a comparison chart of communication costs in an embodiment of the present invention; Figure 6 This is a diagram showing the result of the original PUF before it was obfuscated in an embodiment of the present invention; Figure 7 This is a diagram showing the result of the same pair of CRPs being obfuscated in an embodiment of the present invention; Figure 8 The images show the results of different pairs of CRP obfuscation in the embodiments of the present invention. Detailed Implementation

[0017] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0018] With the development of the Internet of Vehicles, people's demands for data security and privacy security of mobile devices are constantly increasing. Traditional identity authentication protocols are difficult to meet the current requirements of mobile devices for computing and storage capabilities. To address this issue, many scholars have attempted to integrate Physically Unclonable Functions (PUFs) into mobile devices to replace traditional identity authentication methods, and to design authentication protocols based on PUFs for resource-constrained mobile devices. A PUF uses the uncontrollable, minute deviations caused by the manufacturing process of integrated circuits as a unique identifier for the hardware device. These deviations are caused by limitations in the manufacturing process; even if the same hardware device is produced on the same production line, it cannot be copied or controlled by humans. Therefore, it possesses uniqueness and unclonability, making it impossible for attackers to clone a PUF encryption circuit with the same random deviations using the same process, even if they know the structure of the PUF. Therefore, the unique response generated by the PUF to any input challenge is unpredictable and difficult to clone, which can be used to provide effective protection for information.

[0019] To address the security challenges faced by V2G networks, including data privacy protection, resource constraints, vulnerability to eavesdropping during communication, and the security issues of traditional authentication protocols, some scholars have proposed a privacy-preserving two-way authentication protocol based on Puzzle-Based Authentication (PUF). This protocol combines privacy-preserving authentication with fuzzy extraction technology to meet users' privacy protection needs. Other scholars have proposed a lightweight authentication protocol based on PUF, designing a session key mechanism that requires no additional computation or communication overhead. Still others have proposed a privacy-preserving authentication protocol based on PUF that incorporates blockchain technology to protect user privacy through smart contracts. Some scholars have proposed a lightweight anonymous identity authentication protocol based on PUF, addressing the issue that complex security primitives are unsuitable for resource-constrained devices. Some scholars have proposed a vehicle-to-everything (V2X) anonymous authentication protocol based on PUF, fuzzy extractors, and elliptic curves, solving the security problems of identity spoofing and privacy leaks in V2X networks. Finally, some scholars have proposed a lightweight anonymous authentication protocol based on PUF, fuzzy extractors, and elliptic curves, which addresses the vulnerability of data to eavesdropping, forgery, and tampering during network transmission. Regarding the security issues of mobile devices being vulnerable to various forms of cyberattacks, some scholars have successfully resisted spoofing attacks by using the Response generated by PUF instead of the string used for message encryption, generating a successful response. Scholars have pointed out the vulnerability of the Dolve-Yao model to man-in-the-middle attacks and have improved the protocol, successfully solving this problem. Other scholars have proposed using the PUF's response as a temporary key to encrypt communication messages, solving the challenge-response pair storage problem and successfully resisting man-in-the-middle attacks. A PUF-based authentication scheme has been proposed where the CRP is not explicitly stored, successfully resisting machine learning attacks. A PUF-based RFID security authentication protocol has been proposed, addressing the system's vulnerability to physical and cloning attacks. A dual-PUF-based RFID authentication protocol has been proposed, resisting desynchronization and impersonation attacks. A physically secure and conditional VANET key protocol scheme has been proposed, which combines elliptic curve cryptography and PUF to achieve mutual authentication and key negotiation between vehicles and RSUs. Furthermore, it eliminates the need for a TA (Trusted Authority) during authentication and key agreement. However, vehicles publish their long-term public key during registration, allowing attackers to link aliases to vehicles based on the immutable long-term public key. Scholars have proposed a V2I (Vehicle-to-Infrastructure) and V2V (Vehicle-to-Vehicle) authentication scheme based on elliptic curve cryptography and conducted batch verification. The RSU (Remote Authentication Unit) can perform batch authentication of vehicles without a TA (Technical Authentication Token), improving system performance and reducing system overhead. Simultaneously, this scheme combines PUF (Personalized Key Authentication) with biometric keys to resist RSU capture attacks and onboard unit (OBU) intrusion attacks. However, this scheme does not consider the freedom of key escrow.Some scholars have proposed an identity authentication protocol that allows registration on a TA without the TA's involvement. This protocol achieves mutual authentication and key negotiation by combining ECC and PUF, and using PUF to prevent the physical extraction of secrets from the vehicle and RSU.

[0020] However, the long-term key generated by the TA used in multiple authentication processes for the same vehicle remains unchanged. The leakage of the TA can allow attackers to obtain the corresponding secret parameters. Attackers can collect a large number of CRPs in public channels and use machine learning technology to train a mathematical model of PUF, thereby impersonating legitimate devices and causing the leakage of users' location privacy and behavioral habits, which poses a security risk.

[0021] Based on this, the present invention proposes a vehicle network identity authentication protocol based on PUF. This protocol mainly relies on hash functions, PUF and XOR operations to complete identity authentication and key exchange between the vehicle and the RSU.

[0022] A. A model of a vehicle-to-everything (V2X) authentication system based on the improved PUF method, as follows: Figure 1 As shown, in the vehicle-to-everything (V2X) authentication protocol, the Trusted Authority (TA) is a key entity with powerful computing and storage capabilities. It is typically assumed to be completely trustworthy and is primarily responsible for the registration and management of vehicles and Roadside Units (RSUs), providing trust guarantees to the RSUs and ensuring that the RSUs can verify the vehicle's identity during the authentication process. It also assists in key management and privacy protection. In the V2X authentication protocol, the vehicle is the main entity for information perception and communication in the V2X system. It has relatively weak computing and storage capabilities and mainly communicates with the RSU, TA, and Vehicle through the On-Board Unit (OBU), making it vulnerable to attacks that could lead to identity leakage. The RSU, in the V2X authentication protocol, is a roadside unit in the vehicle-road-cloud cooperative system. It has moderate computing and storage capabilities and is responsible for collaborating with the Trusted Authority (TA) to verify the vehicle's legitimate identity, feedback the authentication results to the vehicle, establish session keys with the vehicle, and transmit roadside information.

[0023] B. Threat Model: In the vehicle-to-everything (V2X) authentication protocol, the TA (Trusted Entity) is the core trusted entity, responsible for key functions such as vehicle and RSU (Responsible Unit) registration, key management, and authentication. It is assumed to be completely trusted and its storage will not be leaked. The RSU and Vehicle are considered semi-trusted, and their storage is vulnerable to leakage. However, the RSU's identity is known to all entities. Finally, the adversary's assumptions are as follows: (1) An attacker can obtain the storage information of the RSU or Vehicle but not both at the same time.

[0024] (2) Attackers can eavesdrop, steal, intercept, and modify all information transmitted between vehicles and RSUs, and between vehicles.

[0025] (3) An adversary can perform any physical or machine learning attack to obtain any parameters stored in the vehicle and RSU.

[0026] C. Elliptic Curve Cryptosystem: Assume E is an elliptic curve defined on the finite field GF(q); #E(GF(q)) represents the number of points on the elliptic curve that satisfy the equation. P is a base point of order n on the elliptic curve E. For a prime number field, its equation is: , 0 and Participant A's private key is The public key is The public-private key pair, similar to B and C, is ( , )and( , ).

[0027] Computational Diffie-Hellman problem (CDHP): Given , , ,in It is difficult to calculate within the time limit of a polynomial attack (PPT). P , P , P .

[0028] Physically Unclonable Function (PUF): To ensure highly secure hardware-level identity verification and key generation in resource-constrained and environmentally variable Vehicle-to-Everything (VANET) networks, this invention employs a Self-adaption Deviation Locking PUF (SDL PUF) based on a Self-Timed Ring (STR). While traditional PUFs based on ring oscillators (ROs) have simple structures, their frequency output is easily affected by noise factors such as operating voltage and ambient temperature, leading to an increased Bit Error Rate (BER) and insufficient reliability, making them unsuitable for direct application in vehicle security modules with stringent stability requirements. The SDL PUF, through innovative circuit design and configuration mechanisms, effectively overcomes these shortcomings. Its core principles and characteristics are as follows:

[0029] (1) Core Structure and Adaptive Locking Mechanism: The SDL PUF consists of a set of paired self-timing loops (STRs). During the initialization phase, the SDL PUF introduces an adaptive configuration process. This process dynamically adjusts the internal parameters of the STR pairs, thereby actively amplifying the inherent frequency deviation between the paired STRs. This "locked" significant frequency difference, as an amplified manifestation of uncontrollable process deviations during chip manufacturing, forms the stable basis of the PUF response. Even under external noise interference, this locked relative deviation remains stable, thus significantly reducing response bit errors caused by environmental fluctuations.

[0030] (2) Obfuscation mechanism against side-channel attacks: To further enhance security, the SDL PUF integrates a comparator obfuscation mechanism. When generating the response bit, the comparator operation used to compare the outputs of the two STRs is dynamically randomized. This randomization disrupts the fixed correspondence between the response bit and a specific STR or comparison path, thereby effectively reducing the possibility of modeling or inferring the internal structure of the PUF through side-channel attack methods such as power analysis.

[0031] (4) Reliability Quantification: The reliability of PUF is usually defined as the consistency of the responses obtained when querying the same challenge multiple times under different environmental conditions. Its quantification formula is as follows:

[0032] ; in, This is the reference response under nominal conditions (e.g., normal temperature and pressure). For the first The responses measured under different environmental conditions (such as varying temperature and pressure). For response length, Let be the Hamming distance function. An ideal high-reliability PUF should maintain near-zero bit errors under various environmental noise conditions.

[0033] (5) Experimental performance evaluation: Measured data on the Xilinx Virtex-6 FPGA platform show that the SDL PUF performs well over a wide temperature range ( ) and wide pressure range ( Within its operating range, it achieved a 0% bit error rate, demonstrating its excellent environmental robustness. Simultaneously, it maintained good uniqueness (49.29%, close to the ideal 50%) and uniformity (49.84%, indicating a balanced distribution of 0 / 1 bits). For example... Figure 2 As shown, compared with common PUF types such as Arbiter PUF and RO PUF, SDL PUF can maintain the highest reliability under different noise levels.

[0034] In summary, the SDL PUF model provides a hardware trust source that balances high reliability, strong physical security, and lightweight implementation for this protocol, and is a key technology for building the entire lightweight, model-resistant authentication protocol.

[0035] Design Goals: In the context of connected vehicles, the cryptographic technologies used, including PUF (Power Activated Functions), have stringent security requirements for their authentication and encryption protocols. These protocols must meet the following security requirements and resist the following attacks:

[0036] (1) Mutual authentication: Two-way authentication is required between the vehicle and the RSU to ensure the legitimacy of the identities of both parties in the communication.

[0037] (2) Key negotiation: A session key is generated during the authentication process for subsequent secure communication.

[0038] (3) Anti-attack capability: The protocol should be able to resist common network attacks, such as man-in-the-middle attacks, replay attacks, impersonation attacks and session key attacks.

[0039] (4) Physical security: Prevent attackers from extracting sensitive information through physical capture devices.

[0040] (5) Anonymity: Vehicles should remain anonymous during communication to protect user privacy.

[0041] (6) Unlinkability: Attackers cannot link the old and new pseudonyms of the vehicle.

[0042] (7) Defend against modeling attacks: Obfuscate the challenge-response pair (CRP) of PUF to prevent attackers from directly obtaining CRP for machine learning (ML) modeling attacks.

[0043] The symbols used in the PUF-based vehicle network identity authentication protocol are shown in Table 1: Table 1. Symbols and their descriptions This invention employs random numbers and hash functions, and introduces a challenge / response mechanism in RSU and Vehicle, proposing a vehicle-to-everything (V2X) authentication and key negotiation protocol based on identity and challenge value, without requiring the participation of a TA (Target Attorney). This protocol achieves registration, mutual authentication, and key negotiation through the following steps, and also enables identity updates.

[0044] The method specifically includes the following steps: S1, Vehicle Registration Phase.

[0045] First, each vehicle needs to provide its ID and CRP to TA for registration. Table 2 shows the vehicle registration process.

[0046] Table 2 Vehicle Registration Stage (1) Vehicle Choose a challenge value A vehicle identity The vehicle sends through a secure channel , .

[0047] (2) Upon receiving the message sent by the vehicle , Then, TA first verifies Then generate a random number. And choose a challenge value and generate a response key. and calculate Then send via secure channel .

[0048] (3) Vehicles calculate PUF and will Divided into two parts and , , Finally, store { , }, and published on public channels .

[0049] S2, RSU Node Registration Phase: The RSU can simultaneously transmit its ID and CRP to the TA along with the vehicle, completing the registration process. Table 3 illustrates the RSU registration process.

[0050] Table 3 RSU Node Registration Phase (1) Roadside unit Choose a challenge value and an RSU status The vehicle sends through a secure channel , .

[0051] (2) Upon receiving the message sent by the RSU , Then, TA first verifies Then generate a random number. And select the same challenge value and generate a response key. and calculate Then send via secure channel .

[0052] (3) Roadside unit calculate PUF and will Divided into two parts and , , Finally, store { , }, and published on public channels .

[0053] S3. Mutual Authentication and Key Negotiation Phase: In this phase, the RSU and Vehicle complete the mutual authentication and key negotiation process without the assistance of the TA. Table 4 shows the specific mutual authentication and key negotiation process.

[0054] Table 4 Mutual Authentication and Key Negotiation Phase 1) Vehicle first generates random numbers Then randomly select one response value Calculate the response value and calculate , Public key And the pseudonym for Vehicle Generate a random timestamp ,calculate Vehicles send information via public channels. .

[0055] 2) The RSU receives information from the vehicle's public channel. Then, the vehicle checks the timestamp. The validity of and verification Does it exist? And generate two new random numbers. Then select Challenge value ,calculate And calculate the public key. and calculation Then check and If they are equal, the session is terminated, and a new timestamp is generated upon successful completion. Calculate the fake key and new fake signatures ,calculate Finally, the RSU sends the data via a public channel. To the vehicle.

[0056] 3) Upon receiving the RSU's message transmitted via a public channel Then, the RSU first verifies the timestamp. Is it valid? Then calculate. , and check and If the pairs are equal, continue; otherwise, terminate the session and calculate the session key. Generate a new timestamp ,calculate and update , That is , Replacing each and Finally, it is sent to the RSU via a public channel. .

[0057] 4) Upon receiving the message sent by the Vehicle After receiving the information, the RSU first checks the timestamp. Is it valid? Then calculate. , and examine and Check if they are equal; otherwise, terminate the session. Finally, update. , That is , Replacing each and .

[0058] Finally, the mutual authentication and key negotiation process is completed.

[0059] S4, parameter and password update phase.

[0060] exist After completing a round of mutual authentication and key negotiation with the vehicle, both parties will refresh their local storage parameters to ensure long-term security and session independence.

[0061] (1) Vehicle-side update: The vehicle will update the random number from the previous round. Replace with the newly generated value ,Will Derivative Secrets Update to new token and use new Challenge-response pairs repackage their auxiliary data: and . tuple This will overwrite the old auxiliary data.

[0062] (2) Client update: Similarly, Use the random numbers from the previous round Replace with the newly generated value ,Will Derivative Secrets Updated to and use New Challenge-response pairs recalculate their auxiliary data: and . tuple This will overwrite the old auxiliary data.

[0063] (3) Public token update: As part of the previous round of mutual authentication and key negotiation, the public token will be rotated: and They were respectively and Alternative. This periodic refresh prevents associations between sessions and enhances forward / backward confidentiality.

[0064] S5, User's SDL PUF obfuscation stage.

[0065] In vehicles and During the registration and certification process, when the vehicle and The number exceeds the threshold To defend against machine learning and deep learning attacks, Algorithm 1 from Table 5 is used: To update parameters and In Algorithm 1, the value It is a random value from the current protocol process, and Refer to all parties The generated challenge-response pair. Value It is the timestamp of the current session, vehicle and Each stores a dynamic offset. This offset is updated during each session.

[0066] Table 5 Algorithm 1 DRO_Obfuscate Formal security analysis follows the Real-or-Random (ROR) framework to analyze the confidentiality of session keys and uses a pair-based model to analyze mutual authentication. Then, through the combination of two subsections, the formal security analysis is completed, proving that it guarantees the security of mutual authentication and key negotiation.

[0067] Security model for session key confidentiality: Participants and Session: Each vehicle and Multiple concurrent instances can be run. and ,in For local indexing. An instance either ends with an accept state, outputting a session key. and a session identifier Alternatively, it can end with a rejection status.

[0068] A review of symbols in MAKA: The three authentication messages in a single protocol execution are: ; ; .

[0069] The quantities used in MAKA (as defined in the protocol section) include: ; ; ; ; ; ; ; ; ; ; ; .

[0070] Session identifiers are ordered concatenations: .

[0071] Adversary Models and Oracles. A Probabilistic Multinomial-Time Adversary (PPT) Interact with challengers through the following oracles:

[0072] In the active attacker model, targeting instances Passing messages And receive the corresponding response.

[0073] Generating verifiers under passive eavesdropping conditions With the witness A complete and honest record of an interaction between them.

[0074] Use input Query random oracle This is achieved through lazy sampling and ensures consistency across repeated queries.

[0075] Return and device and challenges The corresponding physically non-clonable function response employs an inert and repeatable consistent evaluation model; for previously unseen device-challenge pairs, based on... The unpredictability abstraction outputs a uniformly random string.

[0076] Output a valid protocol instance. The associated session key.

[0077] In a fresh and accepted instance The above is executed exactly once; if the hidden bit is... Then return the actual session key, if It then returns a uniformly random key.

[0078] Freshness: An accepted instance It is considered fresh if it meets all of the following criteria: Neither the paired instances nor their counterparts have been subjected to Query; The adversary did not simultaneously steal the long-term secret keys of both communicating parties in the same session—the system model of this invention allows for leakage by one party, but never allows for simultaneous leakage by both parties; The timestamps and random numbers used in the session meet the freshness requirement, meaning they are uniformly random and have not been reused in previous or concurrent sessions.

[0079] Advantage: Define the opponent's advantage as ,in yes right Hidden bits in query That's just speculation.

[0080] Adverse events: This invention decomposes the opponent's success into a series of mutually exclusive events: Cracking To calculate or distinguish or Hidden in contribute.

[0081] Predicting the unseen Output, or violation of the fuzz extractor The correctness / leakage assumption.

[0082] Random oracles with precise test key input A collision occurred.

[0083] Session collision / guessing: A different session generated the same session as the test session. enter.

[0084] Violation of freshness rule: During the same round of operation, the long-term keys of both parties were simultaneously leaked.

[0085] Game Sequences and Boundaries: Let In the game The advantage of the opponent.

[0086] : The real Games, i.e. .

[0087] :Will Programming as a lazy ,Right now .

[0088] Idealized That is, for each device / challenge pair, answer with a new uniformly random string. The query should remain consistent when repeated. and The unpredictability of security means .

[0089] Blinding That is to say, and Internally composed of The exported items are replaced with uniformly random values. Any distinguishable case can be used to construct a... Solver, therefore .

[0090] Key independence, that is, under certain conditions The opponent never queried the exact test input, nor were there any other session records that produced the same input. middle, The returned test key is completely independent, therefore .

[0091] The probability boundary of adverse events is calculated as follows: ; ; .

[0092] Summing the losses at each step, we get: .

[0093] therefore, The protocol's session key is implemented Indistinguishability.

[0094] Mutual authentication security mode: Pairing and Session Matching: Let If two accepted instances share the same session identifier. And play complementary roles, for example, vehicles and If each instance of an accepting state has a unique and matching paired instance, except for negligible probability, then the protocol achieves mutual authentication.

[0095] Session record binding: Message Includes numerical values It achieves this through shared elements. , , as well as and Protected components ,Will and Perform cryptographic binding. Conversely, the message... Include The session key is calculated as follows: . and Both contain pairs of tuples A hash reference, thus providing access to the message throughout the session record. and End-to-end authentication.

[0096] Adversary success event: An accepting state instance without a unique pairing instance must originate from one of the following abilities of the adversary: : Impersonation, that is, forging a valid document accepted by the vehicle. For this agreement to be effective Accepted by the vehicle, opponent A tuple that can be correctly bound must be generated. effective and subsequently via session key Below Confirmation via key. This is only possible with key verification. Capable of calculating item Or restore However, both were The difficulty and The unpredictability is excluded, or in the query used for derivation. Precise input It will only be successful in time. Therefore, .

[0097] Vehicle counterfeiting, also known as forgery. Valid message received Regarding this agreement, and the circumstances... Symmetry requires forgery Value binding is required. This, in turn, depends on acquiring unseen data. Response or crack Or, it can successfully guess a random oracle query that matches the complete key derivation input. Therefore, .

[0098] Man-in-the-middle or parallel session attacks: These attacks involve transferring portions of an external protocol session record into the current session. In the context of the protocol, this occurs because... Verified ,and All fields are included In the middle, and In the new session key The following provides information on and For authentication, any attempt to splice messages from different session records requires a random oracle collision on the full key input, or successful cracking. Unpredictability. Therefore, .

[0099] This bypasses the freshness check, meaning it successfully passes the validity checks of timestamps and random numbers across different sessions by reusing or predicting them. Session freshness in the protocol relies on bidirectionally generated, independently generated timestamps and random numbers. The probability of an adversary successfully guessing these values ​​is at most [missing value]. ,in The minimum entropy representing the freshness of a material is modeled as... Internal security hash.

[0100] The final result made This indicates the total number of honest conversations considered. Define the event. This is an accepting state where there is no unique paired instance. According to the formula:

[0101] .therefore, The protocol enables mutual authentication.

[0102] Informal analysis: Proposition SF1: Preventing replay attacks Proof: The proposed The protocol prevents replay attacks by implementing a freshness check. In this protocol, each session dynamically generates new random numbers. As a starting point, these random numbers and timestamps guarantee the uniqueness of each session, ensuring that any intercepted messages cannot be reused in subsequent sessions. Furthermore, the protocol requires each new session to contain unique information originating from each device. The only challenge is the response pair. This mechanism effectively prevents the replay of previous messages and ensures that any replay attempts are detected immediately during the mutual authentication process.

[0103] Proposition SF2: Mitigating Impersonation Attacks Proof: The agreement is reached through vehicles and... Mutual authentication between the two parties mitigates spoofing attacks. The two parties have integrated... The binding mechanism employs a challenge-response mechanism for mutual authentication. Specifically, the vehicle sends a message containing a pseudonym. Binding value Messages of other session parameters . Upon receiving Then, calculate its own binding value. It also verifies the consistency of received values, thereby ensuring that the message originates from a legitimate and authenticated entity. Furthermore, it integrates... This ensures that the identity of each device is cryptographically bound to its unique physical characteristics, making it impossible for adversaries to clone devices or impersonate legitimate vehicles. It is computationally infeasible.

[0104] Proposition SF3: Defending against Man-in-the-Middle (MITM) Attacks Proof: The proposed protocol enforces vehicle-to-vehicle communication before session key establishment. Mutual authentication between the parties is used to prevent man-in-the-middle attacks. During the initial message exchange, both parties transmit their respective binding values ​​( and The protocol verifies the consistency of all authentication and key negotiation messages. This two-way authentication mechanism ensures that neither party can be impersonated, thus preventing adversaries from intercepting or tampering with messages during transmission. Furthermore, the protocol employs end-to-end encryption for all authentication and key negotiation messages. Session key. It is calculated only after successful mutual authentication, ensuring that the key derivation process is protected from interference. Interference. Also includes a key confirmation token. It provides clear evidence that both parties have derived the same session key, eliminating the possibility of undetected manipulation during the key exchange process.

[0105] Proposition SF4: Implement mutual authentication and key negotiation prove: The protocol uses a challenge-response mechanism and is based on The key exchange enables mutual authentication and key negotiation. Each vehicle generates a unique pseudonym and binding value. and transmit to . Upon receiving the message, verify the validity of the binding and calculate its own binding value. Once the vehicle receives In response, the session key is derived using shared parameters. Ensure vehicles and Establish identical session keys. Furthermore, the protocol utilizes... Ensure the confidentiality and integrity of session keys. This is achieved through fusion-based... The challenge-response pair ensures that only authenticated parties can successfully calculate the session key, thus protecting against attacks such as key recovery.

[0106] Proposition SF5: Guaranteeing User Anonymity Proof: User anonymity is a fundamental privacy requirement in connected vehicles. This protocol achieves this by generating dynamic pseudonyms for each session. and To ensure user anonymity, these aliases are used for communication between vehicles and roadside units, preventing adversaries from associating a specific vehicle's identity with messages transmitted across multiple sessions or its physical location. This feature is crucial in connected vehicles because protecting the confidentiality of vehicle location and movement patterns is extremely important. Furthermore, the protocol utilizes highly reliable... To protect the vehicle and This verifies the true identity of the individual and prevents unauthorized entities from tracking or tracing them.

[0107] Proposition SF6: Mitigating Known Session Key Attacks Proof: This protocol mitigates known session key attacks by generating a new key for each communication session. The session key consists of a unique random number, based on... The protocol is derived from a combination of challenge-response pairs and secure key derivation functions. This design ensures forward security, meaning that even if an adversary steals a session key in one session, they cannot use it to derive keys for other sessions. Furthermore, the protocol incorporates a key verification mechanism. and To verify the vehicle and Whether the same session key is calculated prevents key mismatch and ensures that only authenticated parties with valid credentials can establish a shared key, thereby thwarting unauthorized key derivation attempts.

[0108] Proposition SF7: Robustness against physical attacks Proof: This protocol integrates It exhibits high reliability and robustness under varying noise conditions. Furthermore, It is inherently unclonable and difficult to extract or copy. Even if an attacker physically gains access to the device, they cannot replicate its challenge-response behavior or extract the underlying encryption key. Even if an attacker obtains... of The protocol itself Obfuscation schemes and targeting The security is also ensured through corresponding modeling attack tests performed on the vehicle's stored parameters. Therefore, it is resistant to tampering, cloning, side-channel, and modeling attacks. Thus, even if the hardware is directly damaged, its internal state and encryption keys remain protected.

[0109] Proposition SF8: Reduce the impact of denial-of-service attacks Proof: This protocol mitigates the impact of denial-of-service attacks by using cryptographic random numbers and session identifiers in each message exchange. These elements guarantee message uniqueness and prevent replay attacks by ensuring each message is valid only within its specific session context. In the event of a denial-of-service attempt, built-in freshness checks and rate limiting mechanisms restrict the processing of stale or excessive requests, thereby minimizing resource exhaustion. This benefits legitimate vehicles and The availability of critical communication channels was preserved, ensuring the network could continue to operate even under adversarial conditions.

[0110] The protocol used in this invention can complete multiple authentications of the same user through the parameter update phase, which avoids the deficiency of CRP not being updated. At the same time, it can effectively resist machine learning attacks when different users register.

[0111] like Figure 3 As shown in the left figure, CRP obfuscation occurs at different stages of user registration: (1) Randomly selecting challenge values Input to user Generate response value And divided into two parts (2) Select a random number generated by TRNG. and XOR Generate obfuscated response value (3) Select a random challenge value generated by TRNG. And enter it into TA's Generate response value R and XOR Generate obfuscated response value CRP obfuscation occurs during multiple authentication phases for the same user: (1) When starting the next authentication after each authentication is completed, the user selects the appropriate authentication method. The generated random challenge value C is input into the user's PUF to generate a response value R; (2) the response value R is divided into two parts. (3) Select from , Generated random numbers Then, the first registration of the same user is used. Generate response value R XOR and XOR the result XOR (4) Output the result of the XOR operation in the previous step as the obfuscation response value. , (5) For those by The generated random value will be replaced by a new challenge value after the same user's protocol authentication process is completed. C , and by The generated random values, and the same user's protocol authentication process, will both generate similar values. This ensures that each authentication is unique, and by The generated random value is used in the same user's protocol authentication process. The data is encrypted using appropriate cryptography and then XORed with the result of the previous round to complete the update. This ensures that the CRP generated by multiple authentications by the same user and the XORed random number are completely different, all parameters are updated, and this process can be completed without the user's involvement. Experiments were also conducted to verify the results regarding resistance to machine learning attacks, and the results were quite significant.

[0112] Resistance to modeling attacks: from Figure 6 , Figure 7 , Figure 8 As can be seen, when transmitting SDL PUF challenge-response pairs (CRPs) on a public channel, the accuracy against modeling attacks increases from 70% to 95%. When the number of authenticated users approaches 1000, this accuracy approaches 97%. However, starting with the applied SDL PUF obfuscation algorithm, the accuracy against modeling attacks starts at 50%, increases to approximately 58% when the number of users reaches 1000, and remains relatively stable. Furthermore, the obfuscation scheme used in this algorithm is only completed during the registration phase, exhibiting significant lightweight characteristics. Meanwhile, the accuracy against modeling attacks during the parameter update phase is between 48% and 52%. Compared to standard obfuscation methods, the registration and authentication process of this invention provides effective resistance to modeling attacks while achieving maximum lightweighting, reducing the attack success rate by approximately 35%.

[0113] Comparison of computational costs: Computational time cost refers to the time consumed by the Vehicle and RSU in identity authentication and key negotiation. Since the compared protocols all involve hash functions and XOR operations, and some also involve PUFs (Physically Unclonable Functions), which are hardware components embedded in the participants, their time cost is very small. Therefore, the actual computational cost of the above protocols is calculated using the Python programming language, and the average execution time is calculated after 100,000 actual executions. Here, for hash calculations, the SHA-1 hash function from Python's built-in hashlib is used. For PUF functions, the pypcryptodomex, pypuf, and python-fuzzy-extractor libraries in Python are utilized. Therefore, the cost of the underlying encryption algorithms used in the actual protocols is shown in Table 6, and the computational overhead is as follows: Figure 4 And as shown in Table 7

[0114] Table 6 Computing Device Configuration Table 7 Comparison of Calculation Costs for Various Protocols Communication cost comparison: The calculation of communication cost refers to the public data transmitted between the Vehicle and RSU nodes during the authentication and session key negotiation phases. This part uniformly assumes that the length of the real identity, pseudo-identity, random number, and hash function (SHA-1) output is 160 bits, and the timestamp length is 32 bits. The size of the ECC point containing coordinates (X, Y) is 160 + 160 = 320 bits in this protocol. Total amount of data sent MSG1 = 160 + 160 + 160 = 480 bits Total data volume MSG 2 = 160 + 160 + 32 + 160 = 512 bits. Total data volume MSG 3 = 160 + 32 = 192 bits, total data size total=MSG 1 +MSG 2 +MSG 3 = 1184 bits = 148 bytes Figure 5 A comparison of the communication overhead of the proposed protocol and other related protocols is presented.

[0115] Security Comparison: Given that security is the primary consideration, we first analyze several common security attacks to evaluate the performance of the proposed protocol compared to existing related protocols. The label "Yes" indicates that the protocol supports a specific function or is resistant to a specific attack, while "No" indicates that the function is lacking or that the protocol is vulnerable to the attack.

[0116] Due to inherent design flaws, some existing schemes exhibit significant vulnerability to modeling attacks. Specifically, Guajardo et al. and Sadeghi et al. publicly transmit the challenge value and use the response pair as the symmetric key, while Menet et al. transmits the challenge value and the XOR result of the two PUF responses—both methods are highly vulnerable to modeling attacks due to the exposure of crucial PUF-derived data. In contrast, Van Herrewege et al., Liu et al., and Ponnuret et al. employ publicly transmitted challenge and output hi←Gen(ri), with hi also being publicly disclosed; however, this approach offers only partial resistance to machine learning attacks because it relies on traditional PUFs, which are inherently predictable given sufficient challenge-response pair observations. Similarly, Yanambaka et al. uses publicly exposed challenge-response pairs with minimal cryptographic transformations, making the scheme highly vulnerable to adversarial modeling attacks. The Long et al. scheme requires participating entities to store the original challenge-response pairs, introducing a fundamental risk of parameter leakage, making it susceptible to compromise. Xie et al.'s scheme stores the challenge value and its XOR result with a random number, but does not support multi-party authentication and only provides basic resistance to modeling attacks when the stored parameters are exposed. Furthermore, Chaudhry et al. and Kumari et al. rely solely on ECC without incorporating inherent hardware security mechanisms, leaving them vulnerable to physical and side-channel attacks. Finally, in Rostampour et al.'s scheme, if the parameters stored in SPj are leaked and the password strength is insufficient, attackers may recover the corresponding challenge value through password guessing, resulting in only limited resistance to modeling attacks, as detailed in Table 8.

[0117] Table 8 Comparison of Security Features of Various Protocols This invention addresses the limitations of high-speed mobility and resource constraints in vehicle-to-everything (V2X) communication by developing an authentication protocol that eliminates the need for a TA (Transmitter of Interest) for user authentication. The protocol utilizes pseudonyms and Physically Unclonable Functions (PUFs), and parameter updates can be performed independently without requiring a TA. It leverages high-performance cryptographic tools, including one-way hash functions, bitwise XOR, PUFs, and Elliptic Curve Discrete (ECC) functions, for user authentication. This protocol guarantees known session key security properties, forward security, and resistance to key leakage, spoofing, physical attacks, and machine learning attacks. The invention also demonstrates that users can independently update parameters without the need for a TA and showcases reduced computational and communication costs compared to existing technologies, along with significant improvements in resistance to machine learning attacks. Due to its broad applicability to V2X, this protocol is expected to see wider adoption than traditional methods, and the same principles can be applied to V2V environments as well.

[0118] Based on the same inventive concept, this invention also proposes a vehicle network identity authentication system based on PUF, comprising: Registration unit, used to complete registration at the Roadside Unit (RSU) and vehicle; The first message generation module is used for the vehicle to generate a first random number and a first pseudonym factor; and to restore the first private key and the trusted institution key based on the response value generated by the Physically Unclonable Function (PUF) of the trusted institution stored in the vehicle; to generate a first authentication code based on the first private key, the trusted institution key, the first temporary public key generated based on the first random number, the first pseudonym generated based on the trusted institution key and the first pseudonym factor, and the RSU's public key; and for the vehicle to send a first message to the RSU containing the first pseudonym, the first authentication code, and the first temporary public key.

[0119] After receiving the first message, the RSU generates a second random number and a second pseudonym factor; it reconstructs the second private key and trusted authority key based on the PUF response value stored in the RSU to verify the validity of the first authentication code; after successful verification, it generates a second authentication code based on the temporary identity key calculated based on the first temporary public key and the second random number, the second pseudonym generated based on the first pseudonym and the second pseudonym factor, the first authentication code, and the shared secret of the first temporary public key and the second random number; the RSU sends a second message to the vehicle containing the second pseudonym, the second authentication code, and the second temporary public key generated based on the second random number.

[0120] After receiving the second message, the vehicle reconstructs the temporary identity key based on the shared secret of the second temporary public key and the first random number, and verifies the validity of the second authentication code. After successful verification, the vehicle generates a session key based on the first authentication code, the verified second authentication code, the second pseudonym, and the reconstructed temporary identity key, and sends a third message to the RSU.

[0121] Upon receiving the third message, the RSU generates a session key based on the first authentication code, the second authentication code, the second pseudonym, and the temporary identity key, and verifies the third message to complete the two-way authentication and key negotiation between the vehicle and the RSU.

[0122] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A vehicle-to-everything (V2X) identity authentication method based on PUF, characterized in that, Applied to a vehicle-to-everything (V2X) system, the V2X system includes a roadside unit (RSU), vehicles, and trusted institutions, the method includes the following steps: The vehicle generates a first random number and a first pseudonym factor; and reconstructs a first private key and a trusted institution key based on the response value generated by the Physically Unclonable Function (PUF) of the trusted institution stored in the vehicle; generates a first authentication code based on the first private key, the trusted institution key, a first temporary public key generated based on the first random number, a first pseudonym generated based on the trusted institution key and the first pseudonym factor, and the RSU's public key; the vehicle sends a first message to the RSU containing the first pseudonym, the first authentication code, and the first temporary public key; After receiving the first message, the RSU generates a second random number and a second pseudonym factor; it reconstructs the second private key and trusted authority key based on the PUF response value stored in the RSU to verify the validity of the first authentication code; after successful verification, it generates a second authentication code based on the temporary identity key calculated based on the first temporary public key and the second random number, the second pseudonym generated based on the first pseudonym and the second pseudonym factor, the first authentication code, and the shared secret of the first temporary public key and the second random number; the RSU sends a second message to the vehicle containing the second pseudonym, the second authentication code, and the second temporary public key generated based on the second random number. After receiving the second message, the vehicle restores the temporary identity key based on the shared secret of the second temporary public key and the first random number and verifies the validity of the second authentication code; after the verification is successful, the vehicle generates a session key based on the first authentication code, the verified second authentication code, the second pseudonym and the restored temporary identity key, and sends a third message to the RSU. Upon receiving the third message, the RSU generates the session key based on the first authentication code, the second authentication code, the second pseudonym, and the temporary identity key, and verifies the third message to complete the two-way authentication and key negotiation between the vehicle and the RSU.

2. The PUF-based vehicle network identity authentication method according to claim 1, characterized in that, First authentication code The generation process is represented as: ; Where H() is the hash function, A timestamp generated for the vehicle. The first pseudonym for the vehicle. The response generated by a physically unclonable function of a trusted institution serves as the shared key. This serves as the identification identifier for the target roadside unit. The first private key of the vehicle Public key of roadside unit registration The shared secret for performing scalar multiplication operations on elliptic curves. For the vehicle, based on the first random number of this authentication The first temporary public key generated.

3. The PUF-based vehicle network identity authentication method according to claim 2, characterized in that, The roadside unit verifies the first authentication code. The validity of the authentication code is specifically determined by calculating its hash value. By judgment Is it equal to the received? Complete the first authentication code Validation of effectiveness; among which This indicates that the roadside unit uses the vehicle's registered public key. With one's own second private key The shared secret of the calculation, the result of which is related to the vehicle's calculation. equal.

4. The vehicle network identity authentication method based on PUF according to claim 3, characterized in that, The temporary identity key By the roadside unit Calculated and passed by vehicles The result is obtained by restoring the original value, where ⊕ represents the XOR operation.

5. The PUF-based vehicle network identity authentication method according to claim 4, characterized in that, Second authentication code The generation process is represented as: , Among them, the vehicle's second pseudonym , The timestamp generated for the roadside unit This is the shared secret between the first temporary public key and the second random number.

6. The PUF-based vehicle network identity authentication method according to claim 5, characterized in that, The validity of the second authentication code is verified specifically by calculating... To verify the second authentication code, and by judging Is it equal to To complete the certification of the roadside unit.

7. The PUF-based vehicle network identity authentication method according to claim 6, characterized in that, The session key is generated independently by the vehicle and the roadside unit, and the set of input parameters on which the session key is generated is consistent; wherein, The session key generated by the vehicle for: ; The session key generated by the roadside unit for: ; in, = ,and = Thus making = .

8. The vehicle network identity authentication method based on PUF according to claim 1, characterized in that, It also includes updating parameters after the key negotiation is completed, including the following steps: The vehicle generates a new response value using the new PUF challenge value and updates its locally stored encryption parameters using the first random number and temporary identity key; The roadside unit generates a new response value using the new PUF challenge value and updates its locally stored encryption parameters using the second random number and temporary identity key.

9. A vehicle networking identity authentication system based on PUF, characterized in that, Applied to a vehicle-to-everything (V2X) system, the V2X system includes a roadside unit (RSU), vehicles, and trusted institutions; the V2X identity authentication system includes: The first message generation module is used for the vehicle to generate a first random number and a first pseudonym factor; and to reconstruct the first private key and the trusted institution key based on the response value generated by the Physically Unclonable Function (PUF) of the trusted institution stored in the vehicle; to generate a first authentication code based on the first private key, the trusted institution key, the first temporary public key generated based on the first random number, the first pseudonym generated based on the trusted institution key and the first pseudonym factor, and the RSU's public key; and for the vehicle to send a first message to the RSU containing the first pseudonym, the first authentication code, and the first temporary public key. After receiving the first message, the RSU generates a second random number and a second pseudonym factor; it reconstructs the second private key and trusted authority key based on the PUF response value stored in the RSU to verify the validity of the first authentication code; after successful verification, it generates a second authentication code based on the temporary identity key calculated based on the first temporary public key and the second random number, the second pseudonym generated based on the first pseudonym and the second pseudonym factor, the first authentication code, and the shared secret of the first temporary public key and the second random number; the RSU sends a second message to the vehicle containing the second pseudonym, the second authentication code, and the second temporary public key generated based on the second random number. After receiving the second message, the vehicle restores the temporary identity key based on the shared secret of the second temporary public key and the first random number and verifies the validity of the second authentication code; after the verification is successful, the vehicle generates a session key based on the first authentication code, the verified second authentication code, the second pseudonym and the restored temporary identity key, and sends a third message to the RSU. Upon receiving the third message, the RSU generates the session key based on the first authentication code, the second authentication code, the second pseudonym, and the temporary identity key, and verifies the third message to complete the two-way authentication and key negotiation between the vehicle and the RSU.