V2X Authentication via Network-Side Area Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vehicle-to-vehicle communication systems based on DSRC technology face high air-interface resource overhead and processing delays due to certificate-based authentication and signature verification, which can impact the efficiency of delay-sensitive communications.
Innovation Solution
A communication method where a network side performs authentication on user equipment (UE) using an authentication vector, allowing UE to perform vehicle-to-everything (V2X) services, reducing the need for certificate-based authentication and signature verification by using area keys for security protection, thereby minimizing air-interface resource usage and processing delays.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication and signature verification are used in vehicle-to-vehicle communication, then security and reliability are improved, but air-interface resource overhead increases and processing delays occur
Solution Approach 1:
The patent segments the authentication process into two parts: network-side authentication (performed once during attachment) and message-level verification (performed on small area key identifiers). This separates the heavy certificate verification from the lightweight message verification, reducing air-interface overhead while maintaining security.
Solution Approach 2:
The patent performs authentication preliminarily at the network attachment stage, where the network side authenticates the UE and configures area keys. This preliminary authentication eliminates the need for repeated certificate exchanges during V2X communication, reducing air-interface resource overhead.
2Reliability
If certificate-based authentication and signature verification are used in vehicle-to-vehicle communication, then security and reliability are improved, but processing time increases
Solution Approach 1:
The patent segments the authentication process into two parts: network-side authentication (performed once during attachment) and message-level verification (performed on small area key identifiers). This separates the heavy certificate verification from the lightweight message verification, reducing processing delays while maintaining security.
Solution Approach 2:
The patent performs authentication preliminarily at the network attachment stage, where the network side authenticates the UE and configures area keys. This preliminary authentication eliminates the need for repeated certificate exchanges during V2X communication, reducing processing delay.
3Reliability
If certificate-based authentication is performed for each message, then authentication security is maintained, but communication efficiency decreases
Solution Approach 1:
The patent segments the authentication process into two parts: network-side authentication (performed once during attachment) and message-level verification (performed on small area key identifiers). This separates the heavy certificate verification from the lightweight message verification, reducing processing delays while maintaining security.
Solution Approach 2:
The patent changes the parameter being verified at the message level from large certificates to small area key identifiers. This parameter change maintains authentication security while dramatically reducing the computational burden and improving communication efficiency.
Data Source
AI summary
A communication method and a related apparatus are disclosed. The method is performed by an MME, including: receiving an attach request message from an eNB, where the attach request message is used to request to attach to a network, and the attach request message includes an identity of the UE; sending, to an HSS according to the attach request message, an authentication data request message including the identity of the UE; receiving an authentication data response message including an AV from the HSS, where the authentication data response message is used to indicate that the authorization on the UE succeeds; and determining, according to the authentication data response message, that the UE is allowed to perform a V2X service, and performing authentication on the UE according to the AV. The method can enable a network side to perform authentication on UE during V2V communication, thereby reducing an air-interface resource overhead.


