面向VANETs的轻量级匿名认证密钥协商协议
网络出版日期: 2025-01-25
基金资助
国家重点研发计划(2022YFB3103500);国家自然科学基金(62302070,62101079,62272073,62402202,62202071);重庆市自然科学基金(cstc2021jcyj-msxm0465,cstc2021jcyj-msxmX0273);重庆市留学人员回国创业创新支持计划(cx2021012);成都市科技计划(2023-YF11-00020-HZ);中国博士后科学基金(2023M740399,2022M710520,2022M710518);教育部装备预研联合基金(8091B032127)
版权
A lightweight anonymous authenticated key agreement protocol for VANETs
Online published: 2025-01-25
Copyright
车辆与路边单元(RoadSide Units,RSUs)之间的认证密钥协商(Authenticated Key Agreement,AKA)协议在车联网(Vehicular Ad-hoc Networks,VANETs)中至关重要。然而,现有的解决方案仍然存在效率低下的问题。为了解决这个问题,提出一种面向VANETs的轻量级匿名AKA协议,支持车辆与RSUs之间的轻量级匿名认证和密钥协商。通过轨迹规划,将车辆的认证信息提前同步到目标RSUs,加速认证,使得RSUs可以在车辆到达之前做好身份验证的准备,并防止可信权威机构(Trusted Authority,TA)干涉车辆与RSUs之间的AKA。采用轻量级加密操作,降低了计算开销和通信开销,确保AKA的高效性。安全分析表明,本方案不仅可以实现匿名性、条件隐私性、假名不可链接性、免密钥托管和物理安全,而且能够抵御大多数已知攻击。对比实验结果表明,此方案在轻量化设计方面优于现有方案。
刘静婷 , 刘高 , 王宁 , 向涛 . 面向VANETs的轻量级匿名认证密钥协商协议[J]. 网络空间安全科学学报, 2024 , 2(5) : 87 -98 . DOI: 10.20172/j.issn.2097-3136.240508
Authenticated key agreement (AKA) protocol between roadside units (RSUs) and vehicles is a crucial aspect of vehicular ad-hoc networks (VANETs). Nevertheless, existing solutions still have the problem of low efficiency. In order to resolve this issue, a lightweight anonymous AKA protocol specifically designed for VANETs was proposed. It supported lightweight anonymous authentication and key agreement between vehicles and RSUs simultaneously. The trajectory planning was employed to synchronize the authentication information of vehicles to target RSUs in advance for accelerating the authentication, ensuring that RSUs were ready for identity authentication before the vehicles arrive, and eliminating the need for the trusted authority (TA) to participate in each mutual AKA instance. By employing only lightweight cryptographic operations, the computational and communication overheads were reduced, guaranteeing the efficiency of AKA. Security analysis demonstrates that this protocol not only achieve anonymity, conditional privacy, pseudonym unlinkability, key escrow freeness and physical security, but also withstand most known attacks. Comparative experimental results indicate this protocol’s superiority compared to existing protocols in terms of efficiency.
Key words: VANETs; authenticated key agreement; lightweight
表 1 本方案与相关工作的比较Table 1 Comparison of our scheme with related works |
| 方案 | 文献 | An | Un | CP | KEF | PS | RI | RMM | RR | RKS | AHC | FA |
| 传统AKA方案 | [7] | ● | ○ | ○ | ● | ○ | ● | ● | ● | ● | ○ | ● |
| [8] | ● | ○ | ● | ○ | ○ | ● | ● | ● | ● | ○ | ● | |
| [9] | ● | ○ | ○ | ○ | ○ | ● | ● | ● | ● | ● | ● | |
| [10] | ● | ○ | ● | ● | ○ | ● | ● | ● | ● | ● | ● | |
| [11] | ● | ○ | ● | ○ | ○ | ● | ● | ● | — | ○ | ● | |
| [12] | ● | ● | ● | ○ | ○ | ● | ● | ● | — | ● | ● | |
| [13] | ● | ○ | ● | ○ | ● | ● | ● | ● | ● | ○ | ● | |
| [14] | ● | ● | ● | ● | ○ | ● | ● | ● | — | ● | ● | |
| 基于PUF的AKA方案 | [15] | ● | ○ | ● | ○ | ● | ● | ● | ● | — | ○ | ● |
| [16] | ● | ○ | ● | ○ | ● | ● | ● | ● | ● | ● | ● | |
| [17] | ● | ● | ● | ○ | ● | ● | ● | ● | ● | ● | ● | |
| [18] | ● | ○ | ○ | ○ | ● | ● | ● | ● | ● | ● | ● | |
| [19] | ● | ● | ● | ○ | ● | ● | ● | ● | ● | ○ | ● | |
| [20] | ○ | ○ | ○ | ● | ● | ● | ● | ● | ● | ● | ● | |
| Ours | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● |
注:An:匿名性;Un:不可链接性;CP:条件隐私性;KEF:免密钥托管;PS:物理安全性;RI:抵御冒充攻击;RMM:抵御中间人攻击;RR:抵御重放攻击;RKS:抵御已知会话密钥攻击;AHC:避免计算和通信方面的沉重负担;FA:形式分析;●:支持;○:不支持或未考虑;—:不适合评估。 |
表 2 符号Table 2 Notions |
| 符号 | 描述 |
| 实体X的公钥/私钥对 | |
| X的物理克隆函数 | |
| 由X运行的模糊提取器的生成算法 | |
| 由X运行的模糊提取器的再生成算法 | |
| 车辆的验证密钥V | |
| 密钥CK的对称加密算法 | |
| 密钥CK的对称解密算法 | |
| 带有密钥IK的哈希信息验证码 |
表 3 BAN逻辑符号Table 3 Notations of BAN-logic |
| 符号 | 描述 |
| 实体P相信公式X | |
| P接收到包含X的信息 | |
| P曾经发送过包含X的信息 | |
| P对X有管辖权 | |
| X是新鲜的 | |
| 密钥K加密X后的密文 | |
| K是P的公开密钥 | |
| P和Q共享私密密钥K |
表 4 BAN逻辑规则Table 4 Rules of BAN-logic |
| 规则 | 含义 |
| 新鲜性规则 | |
| 临时值验证规则 | |
| 组合规则 | |
| 分解规则 | |
| 仲裁规则 | |
| 信息含义规则 |
表 5 密码操作的执行时间Table 5 Execution time of cryptographic operations |
| 描述 | 符号 | 执行时间(ms) |
| 哈希操作 | 0.001 | |
| PUF操作 | 0.324 | |
| 模糊提取操作 | 0.229 | |
| 椭圆曲线标量乘法 | 17.000 | |
| 椭圆曲线点加法 | 0.051 | |
| 对称加密/解密操作 | 0.265 | |
| HMAC操作 | 0.025 | |
| XOR操作 | 0.001 |
表 6 计算开销对比Table 6 Comparison of computation overhead |
| 方案 | 车辆V计算开销(ms) | RSUs/TA计算开销(ms) | 总计算开销(ms) |
| 文献[7] | Tfe+ 24Th+9Tsm+ 3Tpa=153.406 | 9Th+ 3Tsm+ 2Tpa=51.111 | 204.517 |
| 文献[8] | 6Th+ 2Tsm=34.006 | 13Th+ Tsm=17.013 | 51.019 |
| 文献[9] | 6Th=0.006 | 12Th+ 4Tsm+ Tpa=68.063 | 68.069 |
| 文献[16] | 3Tpuf+ 8Th+ 5Tsm+ 4Tpa+Txor=86.185 | 3Tpuf+ 9Th+ 6Tsm+ Tpa+2Txor=103.034 | 189.219 |
| 文献[17] | Tfe+ 5Th+ 5Tsm+ Tpa+2Txor=85.287 | 5Tsm+ 2Tpa+ 4Th+Tpuf+2Txor=85.432 | 170.719 |
| 本方案 | Tpuf+ Tfe+ 4Th+ 2Thm+ 2Tsym+2Txor=1.139 | 2Tpuf+ 2Tfe+5Th+ 2Thm+ 2Tsym+3Txor=1.694 | 2.833 |
表 7 通信开销对比Table 7 Comparison of communication overhead |
| 方案 | 车辆V通信开销(bytes) | RSUs/TA通信开销(bytes) | 总通信开销(bytes) |
| 文献[7] | 400 | ||
| 文献[8] | 364 | ||
| 文献[9] | 128 | ||
| 文献[16] | 156 | ||
| 文献[17] | 208 | ||
| 本方案 | 136 |
| 1 |
JAKUBIAK J,KOUCHERYAVY Y. State of the art and research challenges for VANETs[C]//Consumer Communications and Networking Conference. 2008:912-916.
|
| 2 |
ZEADALLY S, HUNT R, CHEN Y S, et al. Vehicular ad hoc networks (VANETS): status, results, and challenges[J]. Telecommunication Systems, 2012, 50, 217- 241.
|
| 3 |
CUNHA F, VILLAS L, BOUKERCHE A, et al. Data communication in VANETs: protocols, applications and challenges[J]. Ad Hoc Networks, 2016, 44, 90- 103.
|
| 4 |
HUBAUX J, CAPKUN S, LUO J. The security and privacy of smart vehicles[J]. IEEE Security & Privacy, 2004, 2 (3): 49- 55.
|
| 5 |
QU F, WU Z, WANG F, et al. A security and privacy review of VANETs[J]. IEEE Transactions on Intelligent Transportation Systems, 2015, 16 (6): 2985- 2996.
|
| 6 |
KUMAR V, MISHRA S, CHAND N. Applications of VANETs: present & future[J]. Communications and Network, 2013, 5 (1): 12- 15.
|
| 7 |
SUTRALA A K, OBAIDAT M S, SAHA S, et al. Authenticated key agreement scheme with user anonymity and untraceability for 5G-enabled softwarized industrial cyber-physical systems[J]. IEEE Transactions on Intelligent Transportation Systems, 2022, 23 (3): 2316- 2330.
|
| 8 |
WEI L, CUI J, ZHONG H, et al. A lightweight and conditional privacy-preserving authenticated key agreement scheme with multi-TA model for fog-based VANETs[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 20 (1): 422- 436.
|
| 9 |
SON S, LEE J, PARK Y, et al. Design of blockchain-based lightweight V2I handover authentication protocol for VANET[J]. IEEE Transactions on Network Science and Engineering, 2022, 9 (3): 657- 662.
|
| 10 |
ZHANG Y, DENG R H, BERTINO E, et al. Robust and universal seamless handover authentication in 5G HetNets[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (2): 858- 874.
|
| 11 |
ZHU F, YI X, ABUADBBA A, et al. A security-enhanced certificateless conditional privacy-preserving authentication scheme for vehicular ad hoc networks[J]. IEEE Transactions on Intelligent Transportation Systems, 2023, 24 (10): 10456- 10466.
|
| 12 |
LI Q, HE D, YANG Z, et al. Lattice-based conditional privacy-preserving authentication protocol for the vehicular ad hoc network[J]. IEEE Transactions on Vehicular Technology, 2022, 71 (4): 4336- 4347.
|
| 13 |
TAHIR H, MAHMOOD K, AYUB M F, et al. Lightweight and secure multi-factor authentication scheme in VANETs[J]. IEEE Transactions on Vehicular Technology, 2023, 72 (11): 14978- 14986.
|
| 14 |
XIONG H, CHEN J, MEI Q, et al. Conditional privacy-preserving authentication protocol with dynamic membership updating for VANETs[J]. IEEE Transactions on Dependable and Secure Computing, 2020, 19 (3): 2089- 2104.
|
| 15 |
OTHMAN W, FUYOU M, XUE K, et al. Physically secure lightweight and privacy-preserving message authentication protocol for VANET in smart city[J]. IEEE Transactions on Vehicular Technology, 2021, 70 (12): 12902- 12917.
|
| 16 |
LIANG Y, LUO E, LIU Y. Physically secure and conditional privacy authenticated key agreement for VANETs[J]. IEEE Transactions on Vehicular Technology, 2023, 72 (6): 7914- 7925.
|
| 17 |
XIE Q, DING Z, ZHENG P. Provably secure and anonymous V2I and V2V authentication protocol for VANETs[J]. IEEE Transactions on Intelligent Transportation Systems, 2023, 24 (7): 7318- 7327.
|
| 18 |
MA H, WANG C, XU G, et al. Anonymous authentication protocol based on physical unclonable function and elliptic curve cryptography for smart grid[J]. IEEE Systems Journal, 2023, 17 (4): 6425- 6436.
|
| 19 |
BANSAL G, NAREN N, CHAMOLA V, et al. Lightweight mutual authentication protocol for V2G using physical unclonable function[J]. IEEE Transactions on Vehicular Technology, 2020, 69 (7): 7234- 7246.
|
| 20 |
HARISHMA B, MATHEW P, PATRANABIS S, et al. Safe is the new smart: PUF-based authentication for load modification-resistant smart meters[J]. IEEE Transactions on Dependable and Secure Computing, 2022, 19 (1): 663- 680.
|
| 21 |
LI S, XUE K, WEI D S L, et al. SecGrid: a secure and efficient SGX-enabled smart grid system with rich functionalities[J]. IEEE Transactions on Information Forensics and Security, 2019, 15, 1318- 1330.
|
| 22 |
MAES R,VERBAUWHEDA I. Physically unclonable functions:a study on the state of the art and future research directions[C]//Towards Hardware-Intrinsic Security:Foundations and Practice. 2010:3-37.
|
| 23 |
DODIS Y,REYZIN L,SMITH A. Fuzzy extractors:How to generate strong keys from biometrics and other noisy data[C]//Advances In Cryptology-EUROCRYPT 2004:International Conference on The Theory And Applications Of Cryptographic Techniques. 2004:523-540.
|
| 24 |
CHIM T W, YIU S M, HUI L C K, et al. VSPN: vanet-based secure and privacy-preserving navigation[J]. IEEE Transactions on Computers, 2014, 63 (2): 510- 524.
|
| 25 |
SUMRA I A, HASBULLAH H B. Trust levels of vehicular ad hoc network (VANET)[J]. International Journal of Information Technology and Electrical Engineering, 2014, 3 (5): 7- 16.
|
| 26 |
BURROWS M, ABADI M, NEEDHAM R M. A logic of authentication[J]. ACM Transactions on Computer Systems, 1990, 8 (1): 18- 36.
|
| 27 |
WANG M, ZHAO D, YAN Z, et al. XAuth: secure and privacy-preserving cross-domain handover authentication for 5G HetNets[J]. IEEE Internet of Things Journal, 2023, 10 (7): 5962- 5976.
|
| 28 |
LI X, LIU T, OBAIDAT M S, et al. A lightweight privacy-preserving authentication protocol for VANETs[J]. IEEE Systems Journal, 2020, 14 (3): 3547- 3557.
|
| 29 |
VIJAYAKUMAR P, AZEES M, KOZLOV S A, et al. An anonymous batch authentication and key exchange protocols for 6G enabled VANETs[J]. IEEE Transactions on Intelligent Transportation Systems, 2022, 23 (2): 1630- 1638.
|
| 30 |
pycryptodomex[EB/OL]. (2024-01-10)[2024-06-17]. https://pypi.org/project/pycryptodomex.
|
| 31 |
pypuf [EB/OL]. (2021-11-15)[2024-06-17]. https://github.com/nils-wisiol/pypuf.
|
| 32 |
python-fuzzy-extractor[EB/OL]. (2023-06-14)[2024-06-17]. https://github.com/carter-yagemann/python-fuzzy-extractor/tree/master.
|
/
| 〈 |
|
〉 |