Distributed IoV Identity Authentication via Edge Cloud and RSU Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle identity authentication technologies for IoV face challenges in achieving low communication and computational overhead in high vehicle density environments, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

A distributed IoV identity authentication system is proposed, featuring a core cloud, edge clouds, roadside units (RSUs), and terminal vehicles. This system establishes wired and wireless connections to facilitate efficient data processing and authentication, utilizing elliptic curve cryptography and key exchange protocols while incorporating a Cybertwin edge server for real-time data acquisition and backup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If edge cloud authentication is used to reduce central cloud burden and improve real-time performance, then authentication efficiency is improved, but computational and storage resource requirements at edge nodes become very high in high vehicle density environments

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidcomputational and storage resources at edge nodes
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent segments the authentication system into multiple components: vehicles, RSUs, edge clouds, and core cloud. Each component has specific authentication responsibilities, distributing the computational load across the network rather than concentrating it at edge nodes. This segmentation allows efficient authentication while reducing individual node resource requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces RSUs as intermediary entities between vehicles and edge clouds for authentication. RSUs perform initial authentication verification and coordinate with edge clouds, reducing the direct computational burden on edge nodes while maintaining authentication efficiency. The RSU acts as a mediator that handles preliminary authentication tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ECDSA with complex bilinear pairing and inverse operation is used to ensure security, then security is improved, but computational overhead increases and processing time is extended

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the cryptographic parameters and algorithms used in authentication. Instead of using complex ECDSA with bilinear pairing and inverse operations, the system employs simplified cryptographic mechanisms that maintain security requirements while significantly reducing computational complexity and processing time.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts and removes the computationally intensive operations (bilinear pairing and inverse operations) from the authentication process. By eliminating these complex mathematical operations while retaining essential security verification mechanisms, the system achieves both security and efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If centralized authentication solution is used to simplify system architecture, then system complexity is reduced, but the system forms a single point of failure and affects stability and reliability

Engineering Contradiction:
Improvesystem architecture complexityVSAvoidsystem stability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized authentication architecture into a distributed multi-layer architecture involving vehicles, RSUs, edge clouds, and core cloud. This segmentation eliminates the single point of failure by distributing authentication capabilities across multiple independent nodes, thereby improving system stability and reliability while maintaining manageable complexity through clear role definitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic authentication mechanisms where different nodes (vehicles, RSUs, edge clouds) can perform authentication functions based on their capabilities and current system conditions. This dynamic distribution of authentication responsibilities enhances system reliability by providing multiple authentication paths while keeping the overall architecture relatively simple through standardized protocols.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12224994B1Identity authentication system for distributed Internet of vehicles
Publication Date: 2025.02.11 GUANGDONG UNIV OF TECH
  • US12224994B1 patent drawing

AI summary

Disclosed is an identity authentication system for distributed Internet of vehicles (IoV), including a core cloud, a plurality of edge clouds, a plurality of road side units (RSUs) and a plurality of terminal vehicles. The core cloud stores registration information about the terminal vehicles and the RSUs; the edge cloud performs identity verification on the RSUs according to the registration information, and after the verification is passed, the edge cloud generates a temporary shared session key and sends the same to the RSU and the terminal vehicle, and the RSU and the terminal vehicle establish encrypted communication according to the temporary shared session key, to provide a network communication service for the terminal vehicle. In the present disclosure, a vehicle identity authentication efficiency in a scene with a large traffic density can be effectively improved.