Distributed IoV Identity Authentication via Edge Cloud and RSU Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle identity authentication technologies for IoV face challenges in achieving low communication and computational overhead in high vehicle density environments, leading to inefficiencies and potential security vulnerabilities.
Innovation Solution
A distributed IoV identity authentication system is proposed, featuring a core cloud, edge clouds, roadside units (RSUs), and terminal vehicles. This system establishes wired and wireless connections to facilitate efficient data processing and authentication, utilizing elliptic curve cryptography and key exchange protocols while incorporating a Cybertwin edge server for real-time data acquisition and backup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If edge cloud authentication is used to reduce central cloud burden and improve real-time performance, then authentication efficiency is improved, but computational and storage resource requirements at edge nodes become very high in high vehicle density environments
Solution Approach 1:
The patent segments the authentication system into multiple components: vehicles, RSUs, edge clouds, and core cloud. Each component has specific authentication responsibilities, distributing the computational load across the network rather than concentrating it at edge nodes. This segmentation allows efficient authentication while reducing individual node resource requirements.
Solution Approach 2:
The patent introduces RSUs as intermediary entities between vehicles and edge clouds for authentication. RSUs perform initial authentication verification and coordinate with edge clouds, reducing the direct computational burden on edge nodes while maintaining authentication efficiency. The RSU acts as a mediator that handles preliminary authentication tasks.
2Reliability
If ECDSA with complex bilinear pairing and inverse operation is used to ensure security, then security is improved, but computational overhead increases and processing time is extended
Solution Approach 1:
The patent changes the cryptographic parameters and algorithms used in authentication. Instead of using complex ECDSA with bilinear pairing and inverse operations, the system employs simplified cryptographic mechanisms that maintain security requirements while significantly reducing computational complexity and processing time.
Solution Approach 2:
The patent extracts and removes the computationally intensive operations (bilinear pairing and inverse operations) from the authentication process. By eliminating these complex mathematical operations while retaining essential security verification mechanisms, the system achieves both security and efficiency.
3Device complexity
If centralized authentication solution is used to simplify system architecture, then system complexity is reduced, but the system forms a single point of failure and affects stability and reliability
Solution Approach 1:
The patent segments the centralized authentication architecture into a distributed multi-layer architecture involving vehicles, RSUs, edge clouds, and core cloud. This segmentation eliminates the single point of failure by distributing authentication capabilities across multiple independent nodes, thereby improving system stability and reliability while maintaining manageable complexity through clear role definitions.
Solution Approach 2:
The patent introduces dynamic authentication mechanisms where different nodes (vehicles, RSUs, edge clouds) can perform authentication functions based on their capabilities and current system conditions. This dynamic distribution of authentication responsibilities enhances system reliability by providing multiple authentication paths while keeping the overall architecture relatively simple through standardized protocols.
Data Source
AI summary
Disclosed is an identity authentication system for distributed Internet of vehicles (IoV), including a core cloud, a plurality of edge clouds, a plurality of road side units (RSUs) and a plurality of terminal vehicles. The core cloud stores registration information about the terminal vehicles and the RSUs; the edge cloud performs identity verification on the RSUs according to the registration information, and after the verification is passed, the edge cloud generates a temporary shared session key and sends the same to the RSU and the terminal vehicle, and the RSU and the terminal vehicle establish encrypted communication according to the temporary shared session key, to provide a network communication service for the terminal vehicle. In the present disclosure, a vehicle identity authentication efficiency in a scene with a large traffic density can be effectively improved.
