Quantum-computing-resistant, vehicle-to-everything communication on a peer-to-peer network

A system employing stateless few-time signature algorithms with short-term key pairs addresses the quantum computing threat to V2X systems by balancing signature size and computational efficiency, ensuring secure and efficient vehicle communications.

WO2026112455A1PCT designated stage Publication Date: 2026-05-28INTEGRITY SECURITY SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
INTEGRITY SECURITY SERVICES LLC
Filing Date
2025-11-21
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

The development of quantum computing threatens the integrity of existing public key algorithms used in vehicle-to-everything (V2X) architectures, necessitating a transition to post-quantum algorithms that require design changes due to larger signatures and increased computational demands, which are challenging for existing radio channel bandwidth and latency requirements.

Method used

Implementing a system that uses stateless few-time signature algorithms with short-term key pairs, periodically broadcast and validated using long-term post-quantum keys, to secure vehicle communications, balancing signature size and computational efficiency with security lifespan.

Benefits of technology

This approach provides a quantum-safe, efficient, and secure communication solution by using compact signatures and frequent key updates, ensuring reliable and low-latency message validation in V2X systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025056611_28052026_PF_FP_ABST
    Figure US2025056611_28052026_PF_FP_ABST
Patent Text Reader

Abstract

A system for securing a message between a vehicle and second station includes. The second station broadcasts a message and a signed short-term public key. The short-term public key is signed with a long-term private key. The message is signed with a short-term private key. The vehicle station receives the message and the short-term public key from the second station. The vehicle station validates the signature of the short-term public key, stores the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station. The second station generates a new short-term key pair including a short-term private key and a short-term public key. The new short-term public key is signed with the long-term private key. The second station broadcasts a new message short-term public key. The vehicle station validates a signature on the new message using the new short-term public key.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No.: 0252.0032-PCTQUANTUM-COMPUTING-RESISTANT, VEHICLE-TO-EVERYTHING COMMUNICATION ON A PEER-TO-PEER NETWORKCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 723,255 filed on 21 November 2024, which is hereby incorporated by reference in its entirety.FIELD OF THE INVENTION

[0002] This invention relates to the systems, devices, computer applications, and methods for secure communications with, for example, vehicles.BACKGROUND

[0003] The development of effective quantum computing technology may threaten the integrity of most existing public key algorithms currently in use. This includes the elliptic curve algorithm which is critical to many vehicle-to-everything (V2X) architectures. While alternative approved algorithms exist that are believed to be resistant to attacks that use a quantum computer, these algorithms have dramatically larger signatures and public keys than the existing solution. This means that the transition to a post-quantum algorithm may require design changes beyond simply replacing the signature algorithm with an approved variant.

[0004] Accordingly, it is desirable to provide improved systems, methods, products, and techniques for secure communications with vehicles. Various embodiments described herein address the above-noted and other drawbacks associated with conventional systems and techniques for securing communications with vehicles against attacks using quantum computing.SUMMARY

[0005] Embodiments of the disclosure include devices that use an approved postquantum algorithm to periodically broadcast a short-term, limited use key. Examples then use the short-term key to sign individual safety messages until the short-term keyAttorney Docket No.: 0252.0032-PCT expires. Embodiments may be implemented or embodied in the form of devices (e.g., V2X devices, computing systems), processes (e.g., processor-implemented methods), and manufactures (e.g., computer readable media containing program instructions). Examples provided in the disclosure are non-exclusive and are not to be considered as limiting other embodiments of the disclosure.

[0006] In various implementations, a system for securing a message between a vehicle station and second station, includes: a vehicle station configured to be located in a vehicle; and a second station configured to be located at a second station location other than the vehicle. The second station broadcasts a message and a signed shortterm public key. The signed short-term public key is a signed public key of a few-time signature short-term key pair including a short-term private key and a short-term public key. The signed short-term public key is signed with a long-term private key. The message is signed with the short-term private key. The vehicle station is configured to receive the message and the signed short-term public key from the second station. The vehicle station is configured to validate the signature of the signed short-term public key. The vehicle station is configured to store the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station. The second station generates a signed new short-term public key, the signed new short-term public key being part of a new short key pair including a new short-term private key and a new short-term public key. The signed new short-term public key is signed with the long-term private key. The second station broadcasts a new message and the signed new short-term public key. The vehicle station validates a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station. A lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

[0007] In some implementations, the short-term key pair is a stateless few-time signature key pair.

[0008] In some implementations, the short-term key pair is generated using an algorithm.

[0009] In some implementations, the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.Attorney Docket No.: 0252.0032-PCT

[0010] In some implementations, the message and the signed short-term public key are broadcast over a cellular communication channel.

[0011] In some implementations, the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.

[0012] In some implementations, the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.

[0013] In various implementations, a method for securing a message between a vehicle station and a second station includes: generating a message; generating a fewtime signature short-term key pair including a short-term private key and a short-term public key; signing, with a long-term private key, the short-term public key; signing, with the short-term private key, the message; broadcasting, from the second station, the message and the signed short-term public key; receiving, by the vehicle station, the message and the signed short-term public key; validating, by the vehicle station, the signature of the signed short-term public key; storing, by the vehicle station, the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station; generating a new short-term key pair including a new short-term private key and a new short-term public key; signing, with the long-term private key, the new short-term public key; broadcasting, from the second station, a new message and the signed new short-term public key; and validating, by the vehicle station, a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station. A lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

[0014] In some implementations, the short-term key pair is a stateless few-time signature key pair.

[0015] In some implementations, the short-term key pair is generated using an algorithm.

[0016] In some implementations, the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.

[0017] In some implementations, the message and the signed short-term public key are broadcast over a cellular communication channel.Attorney Docket No.: 0252.0032-PCT

[0018] In some implementations, the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.

[0019] In some implementations, the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.

[0020] In various implementations, a non-transitory computer-readable medium between a vehicle station and second station, includes a plurality of instructions that, in response to execution by a processor, cause the processor to perform operations including: generating a message; generating a few-time signature short-term key pair including a short-term private key and a short-term public key; signing, with a long-term private key, the short-term public key; signing, with the short-term private key, the message; broadcasting, from the second station, the message and the signed shortterm public key; receiving, by the vehicle station, the message and the signed shortterm public key; validating, by the vehicle station, the signature of the signed short-term public key; storing, by the vehicle station, the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station; generating a new short-term key pair including a new short-term private key and a new short-term public key; signing, with the long-term private key, the new short-term public key; broadcasting, from the second station, a new message and the signed new shortterm public key; and validating, by the vehicle station, a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station. A lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

[0021] In some implementations, the short-term key pair is a stateless few-time signature key pair.

[0022] In some implementations, the short-term key pair is generated using an algorithm.

[0023] In some implementations, the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.

[0024] In some implementations, the message and the signed short-term public key are broadcast over a cellular communication channel.Attorney Docket No.: 0252.0032-PCT

[0025] In some implementations, the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.

[0026] In some implementations, the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.

[0027] It is noted that all possible combinations of the above features are a part of this disclosure.DESCRIPTION OF THE DRAWINGS

[0028] The accompanying drawings, which are incorporated into and constitute a part of this specification, illustrate embodiments of the invention and together with the description, serve to explain the principles of the invention.

[0029] FIG. 1 is a block diagram showing an example of a system for securing a message between a vehicle station and second station, consistent with implementations of the invention; and

[0030] FIG. 2 is a flow chart showing an exemplary method consistent with embodiments of the invention.DETAILED DESCRIPTION

[0031] Reference will now be made in detail to various implementations of the invention, examples of which are illustrated in the accompanying drawings. Wherever convenient, the same reference numbers will be used throughout the drawings to refer to the same or like parts.

[0032] In order to ensure safe and proper operation in the field, embedded devices, for instance, the Electronic Control Unit (ECUs) used in vehicles, may need to be properly accessed remotely during use. Digital assets could include various cryptographic keys, a unique identifier, digital certificates, and software. It is therefore desirable to create systems and methods to securely communicate with these devices. As described above, this can be challenging in the age of quantum computing.

[0033] The National Institute of Standards and Technology (NIST) has approved a set of post-quantum algorithms for digital signatures. Currently approved algorithmsAttorney Docket No.: 0252.0032-PCT include Dilithium-CRYSTALS and SPHINCS+. Other algorithms, for example the Falcon signature algorithm, are expected to also be approved. The size of the public key and signatures required for these algorithms is typically on the order of 10 times the size of the Elliptic Curve Digital Signature Algorithm (ECDSA) P-256 signatures currently in use for most connected vehicle or V2X systems. These algorithms also require more computing resources to sign and validate individual signatures. The increased size of the signatures and computational delay may make a direct replacement of ECDSA with an approved algorithm technically challenging due to limitations on the radio channel bandwidth available and the need for very low latency.

[0034] Embodiments include a class of algorithms have been proposed with small (on the order of 100 bytes) signatures that are believed to be quantum-safe. These algorithms are generally classified as “stateless few-time signature” or FTS schemes. Non-exclusive examples include: BiBa, Ball in Bin algorithm; HORS, Hash to Obtain Random Subsets; HORST, HORS variant with Trees; PORS, variant with PRNGs; FORS, variant with Forests; TESLA, Timed Efficient Stream Loss-tolerant Authentication; and FLAMeS, Fast, Loss-Tolerant Authentication of Multicast Streams.

[0035] Common properties of these algorithms, in general, are: (1 ) very small signature size (on the order of 100 to 250 bytes); (2) very efficient validation; (3) somewhat efficient signature generation; (4) large public keys (on the order of several KB); (5) security is reduced with each signature produced, limiting the useful lifespan of a private key to a defined number of signatures when a lower threshold of security is defined; (6) simplified stateful operation, meaning that the only “state” information that needs to be maintained by a signer is the number of signatures produced with a given key “a”, where a signer has reliable access to the current time, the life of a key, and the maximum number of signatures that may be associated with the time during which the key is valid.

[0036] In the case of V2X stations, a reliable source of time may be obtained over a GPS receiver. Trust in GPS data is a requirement for basic V2X safety operation, regardless of which digital signature method is used. Techniques exist to improve trust in GPS data. For example, inference may be used to “validate” the consistency of GPS data in a number of ways. A station may enforce that GPS time must be monotonicallyAttorney Docket No.: 0252.0032-PCT increasing, for example, the roll-back of GPS time indicates that GPS signal is invalid. A station may compare GPS time against an internal, free-running Real-Time Clock (RTC) and ensure that the statistics (mean, standard deviation) of the RTC is consistent. A significant change in RTC performance when compared to GPS data over a “short” interval indicates that GPS data may be invalid. A station may use inertial movement estimation and compare the predicted movement against GPS data. A significant change in predicted position error statistics when compared to GPS data indicates that GPS data may be invalid.

[0037] These are some examples of methods that may be used to improve the level of trust in GPS time and location data received by a V2X station. Trust in the unsigned, unsecured GPS data stream is inherent in many V2X applications. Malicious manipulation of GPS signals in an environment where there is no alternative source of time and location can cause failure in any V2X deployment, regardless of the digital signature method used and independent of the threat posed by a quantum computer.

[0038] Under the assumption that a reliable source of time is available to all stations, a quantum-safe FTS algorithm may be used for V2X messages. The small signature size and efficient sign / validate functions allow these algorithms to provide a convenient “drop-in” replacement for ECC signatures. In some cases, the only difference is in the large public key size and relatively short life of each signing key.

[0039] In a hybrid environment, stations may periodically generate a short-term FTS key pair and broadcast the public key, signed using an approved long-term postquantum algorithm (such as Dilithium-CRYSTALS, SPHINCS+, or Falcon). Nearby stations will receive this broadcast over, for example, a shared PC5 (cellular) V2X channel. This broadcast may optionally include a certificate, signed by an approved authority, that validates the authenticity of the public key used to validate the FTS key.

[0040] In embodiments, on receiving a new key, each station will do the following: validate the post-quantum signature on the message; if a certificate was included in the broadcast, validate the certificate; and if the signatures are valid, then store the station ID and FTS public key in a short-term cache.

[0041] In embodiments, after broadcasting a new FTS public key, a station will then use the corresponding secret key to sign and broadcast V2X safety messages.Attorney Docket No.: 0252.0032-PCTNearby stations will use the FTS public key in their short-term cache to validate these signatures.

[0042] In embodiments, during the active life of an FTS signing key, the station that generated that key will periodically repeat the broadcast of the signature and optional certificate needed to validate that key. In embodiments, this will happen at short intervals of, for example, 1 to 5 seconds so that vehicles and infrastructure equipment that has come into range of the station will be able to receive and validate the FTS key and add it to their short-term cache.

[0043] In embodiments, when a short-term FTS signing key reaches the end of life, the station that generated that key will discard it and generate a new FTS key pair, sign it with its long-term post-quantum key pair and broadcast the signed key and optionally include a signed certificate to validate the integrity of the long-term postquantum public key. In embodiments, all stations will maintain a short-term cache of FTS public keys that they have received and validated from nearby stations.

[0044] Embodiments of these systems and methods are intended to strike a balance between large, long-term keys and signatures vs. very compact short-term signatures. In some cases, the larger, long-term keys and signatures are broadcast at a relatively slow rate of once every 1 to 5 seconds. The rate of broadcast can be adjusted based on the vehicle speed and the number of new stations that have come into broadcast range. The more compact, short-term FTS key will be used, for example, to broadcast all safety-critical messages on a much more frequent bases, such as, for example, 10 times per-second.

[0045] In embodiments, stations may also request that a specific station identify itself by broadcasting the signed FTS public key and optional certificate on-demand. For example, a roadside unit (RSU) that has received a Basic Safety Message (BSM) from a vehicle that has just entered its radio receiver’s range, may request that the vehicle immediately send the signed public key. This request may specifically be triggered if the vehicle requests any special permissions, such as signal priority or preemption.

[0046] Figure 1 shows an example of a system in accordance with embodiments of the disclosure. In this example, a second station 15 is located at a message source 10 such as, for example, a land-based, stationary facility. Non-exclusive examples ofAttorney Docket No.: 0252.0032-PCT message source 10 include a building, a road side unit (RSU), or a vehicle. In this example, a vehicle station 25 is located in a vehicle 20. Non-exclusive examples of vehicle 20 include an automobile, a truck, a fire engine, an ambulance, a law enforcement vehicle, farm equipment, and any other mobile device. In this example, the vehicle station 25 and the second station 15 communicate over a bi-directional channel / network 110. As described above, in exemplary embodiments, the channel / network 110 is a cellular channel / network, for example, a PC5 cellular channel / network. In embodiments, channel / network 110 is another type of communication network.

[0047] Figure 2 shows an example of a method in accordance with embodiments of the disclosure. In step 202, a message is generated. In step 204, a few-time signature short-term key pair including a short-term private key and a short-term public key are generated, In step 206, the short-term public key is signed with a long-term public key. In step 208, the message is signed with the short-term private key. In step 210, the message and the signed short-term public key are broadcast from the second station. In step 212, the message and the signed short-term public key are received by the vehicle station. In step 214, the signature of the signed short-term public key is validated by the vehicle station. In step 216, the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station are stored by the vehicle station. In step 218, a new short-term key pair including a new short-term private key and a new short-term public key are generated. In step 220, the new short-term public key is signed with the long-term private key. In step 222, a new message and the signed new short-term public key are broadcast from the second station. In step 224, a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station is validated by the vehicle station.

[0048] In general, the various methods, operations, and functions described herein may be performed, at least partially, by one or more virtual machines (VMs). In additional or alternative implementations, the operations of the applications described herein may be performed, at least partially by one or more processors that are temporarily configured (e.g., by software) or permanently configured to perform theAttorney Docket No.: 0252.0032-PCT relevant operations. Whether temporarily or permanently configured, such processors may constitute processor-implemented modules that operate to perform one or more application operations, functions, and roles described herein. As used herein, the term ‘processor-implemented module’ refers to a hardware module implemented using one or more processors.

[0049] Similarly, the processes, functions, and operations described herein may be at least partially processor-implemented, with a particular processor or processors being an example of hardware. For example, at least some of the operations of a function may be performed by one or more processors or processor-implemented modules. Moreover, the processor(s) may also operate to support performance of the relevant operations in a ‘cloud computing’ environment or as a ‘software as a service’ (SaaS). For example, at least some of the operations may be performed by a group of computers (as examples of machines including processors), with these operations being accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., an API).

[0050] The performance of certain of the operations may be distributed among the processors, not only residing within a single machine, but deployed across a number of machines. In some example embodiments, the processors or processor- implemented modules may be located in a single geographic location (e.g., within an office environment, a manufacturing environment, or a server farm). In other example embodiments, the processors or processor-implemented modules may be distributed across a number of geographic locations.

[0051] Other embodiments of the invention will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. It is intended that this specification be considered as disclosing examples only, with a true scope and spirit of the invention being indicated by the forthcoming claims of the corresponding non-provisional application.

Claims

Attorney Docket No.: 0252.0032-PCTCLAIMSWHAT IS CLAIMED IS:1 . A system for securing a message between a vehicle station and second station, comprising: a vehicle station configured to be located in a vehicle; and a second station configured to be located at a second station location other than the vehicle, wherein the second station broadcasts the message and a signed short-term public key, wherein the signed short-term public key is a signed public key of a few-time signature short-term key pair including a short-term private key and a short-term public key, wherein the signed short-term public key is signed with a long-term private key, wherein the message is signed with the short-term private key, wherein the vehicle station is configured to receive the message and the signed short-term public key from the second station, wherein the vehicle station is configured to validate the signature of the signed short-term public key, wherein the vehicle station is configured to store the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station, wherein the second station generates a new short-term key pair including a new short-term private key and a new short-term public key, wherein the new short-term public key is signed with the long-term private key, wherein the second station broadcasts a new message and the signed new short-term public key, wherein the vehicle station validates a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station, andAttorney Docket No.: 0252.0032-PCT wherein a lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

2. The system of claim 1 , wherein the short-term key pair is a stateless fewtime signature key pair.

3. The system of claim 1 , wherein the short-term key pair is generated using an algorithm.

4. The system of claim 3, wherein the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.

5. The system of claim 1 , wherein the message and the signed short-term public key are broadcast over a cellular communication channel.

6. The system of claim 1 , wherein the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.

7. The system of claim 1 , wherein the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.

8. A method for securing a message between a vehicle station and a second station, the method comprising: generating the message; generating a few-time signature short-term key pair including a short-term private key and a short-term public key; signing, with a long-term private key, the short-term public key; signing, with the short-term private key, the message;Attorney Docket No.: 0252.0032-PCT broadcasting, from the second station, the message and the signed short-term public key; receiving, by the vehicle station, the message and the signed short-term public key; validating, by the vehicle station, the signature of the signed short-term public key; storing, by the vehicle station, the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station; generating a new short-term key pair including a new short-term private key and a new short-term public key; signing, with the long-term private key, the new short-term public key; broadcasting, from the second station, a new message and the signed new short-term public key; and validating, by the vehicle station, a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station, wherein a lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

9. The method of claim 8, wherein the short-term key pair is a stateless fewtime signature key pair.

10. The method of claim 8, wherein the short-term key pair is generated using an algorithm.1 1 . The method of claim 10, wherein the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.

12. The method of claim 8, wherein the message and the signed short-term public key are broadcast over a cellular communication channel.Attorney Docket No.: 0252.0032-PCT13. The method of claim 8, wherein the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.

14. The method of claim 8, wherein the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.

15. A non-transitory computer-readable medium for securing a message between a vehicle station and second station, the non-transitory computer-readable medium comprising a plurality of instructions that, in response to execution by a processor, cause the processor to perform operations comprising: generating the message; generating a few-time signature short-term key pair including a short-term private key and a short-term public key; signing, with a long-term private key, the short-term public key; signing, with the short-term private key, the message; broadcasting, from the second station, the message and the signed short-term public key; receiving, by the vehicle station, the message and the signed short-term public key; validating, by the vehicle station, the signature of the signed short-term public key; storing, by the vehicle station, the validated short-term public key and a station identification of the second station in a short-term cache of the vehicle station; generating a new short-term key pair including a new short-term private key and a new short-term public key; signing, with the long-term private key, the new short-term public key; broadcasting, from the second station, a new message and the signed new short-term public key; andAttorney Docket No.: 0252.0032-PCT validating, by the vehicle station, a signature on the new message using the signed new short-term public key in the short-term cache of the vehicle station, wherein a lifetime of the short-term private key is defined by a number of signatures produced with the short-term private key.

16. The non-transitory computer-readable medium of claim 15, wherein the short-term key pair is a stateless few-time signature key pair.

17. The non-transitory computer-readable medium of claim 15, wherein the short-term key pair is generated using an algorithm.

18. The non-transitory computer-readable medium of claim 17, wherein the algorithm is one selected from the group consisting of: BiBa, HORS, HORST, PORS, FORS, TESLA, and FLAMeS.

19. The non-transitory computer-readable medium of claim 15, wherein the message and the signed short-term public key are broadcast over a cellular communication channel.

20. The non-transitory computer-readable medium of claim 15, wherein the public key is broadcast with a certificate, signed using the long-term private key, that validates the authenticity of the signed short-term public key.21 . The non-transitory computer-readable medium of claim 15, wherein the second station is configured to broadcast the message and the signed short-term public key approximately ten times per second.