Vehicular Pseudonym Certificates for Low-Latency Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle-to-vehicle (V2V) communication systems face challenges in security, particularly with the revocation problem and the need for frequent credential updates to avoid security issues.

Innovation Solution

A token-based vehicular security system (TVSS) that communicates with connected vehicles, issues pseudonym certificates with low latency, and provides a standard unforgeability security guarantee without compromising anonymity or unlinkability, using roadside units (RSUs) to manage credentials and revocation lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials have a relatively long lifespan in current V2V systems, then system complexity is reduced, but security is compromised due to vulnerability to attacks

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic credential lifespan management where pseudonym certificates are automatically revoked and refreshed based on vehicle movement and location changes. The system dynamically adjusts credential validity periods rather than using fixed long-lived credentials, enabling frequent updates without manual intervention while maintaining system manageability through automated lifecycle control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the credential system into multiple pseudonym certificates with short lifespans rather than using single long-lived credentials. Each pseudonym certificate is valid only for specific time periods and locations, dividing the overall security credential into multiple smaller, manageable units that can be independently revoked and refreshed.

Inventive Principle:
Principle #1Segmentation

2Reliability

If vehicles refresh credentials frequently to avoid security issues, then security is improved, but communication overhead and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating batches of pseudonym certificates and storing them locally in vehicles before they are needed. This allows vehicles to quickly access and switch to fresh credentials without real-time communication delays, enabling frequent credential refreshing while minimizing communication overhead and latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements local quality by enabling vehicles to independently manage and refresh their own pseudonym certificates from local storage without requiring continuous backend server communication. Each vehicle maintains its own credential inventory and can autonomously switch credentials based on location and time, reducing centralized communication overhead while maintaining security.

Inventive Principle:
Principle #3Local quality

3Reliability

If pseudonym certificates have short lifespan, then security is improved through frequent updates, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling vehicles to autonomously manage their own pseudonym certificate lifecycles including generation, storage, selection, and revocation without manual intervention. The system automatically tracks which pseudonyms are active, revoked, or expired, and vehicles can independently switch to new credentials based on pre-established rules, reducing operational complexity despite frequent updates.

Inventive Principle:
Principle #25Self-service

4Reliability

If the system maintains anonymity and unlinkability properties, then privacy is protected, but security guarantees become more difficult to provide

Engineering Contradiction:
Improveunforgeability security guaranteeVSAvoidanonymity and unlinkability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces pseudonym certificates as intermediaries between the vehicle's permanent identifier and the communication system. These pseudonyms act as mediators that provide unforgeability security guarantees through cryptographic signatures while simultaneously protecting anonymity and unlinkability by decoupling the permanent identifier from communications. The pseudonyms can be revoked and refreshed without exposing the underlying vehicle identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250128676A1Token-based Vehicular Security System
Publication Date: 2025.04.24 RGT UNIV OF CALIFORNIA
  • US20250128676A1 patent drawing
  • US20250128676A1 patent drawing
  • US20250128676A1 patent drawing

AI summary

A method and apparatus for operating a token-based vehicular security system (TVSS) is disclosed. The method includes communicating with a communicatively connected vehicle (CV) communicatively connected to the token based vehicular security system (TVSS); issuing a pseudonym certificate (PC) to the communicatively connected vehicle (CV) from one of a plurality of roadside units (RSUs) with the token-based vehicular security system (TVSS) having a low latency; and providing a standard unforgeability security guarantee for the token based vehicular security system (TVSS) without violating anonymity or unlinkability properties. The system includes a roadside unit (RSU) communicatively connected to a roadside unit backend included in a cloud computing environment; a certificate authority (CA) included in the cloud computing environment; a SETUP protocol; a TOKENGEN protocol; a PSEUDOGEN; and a REVOKE protocol.