【24h】

Privacy-Preserving Method for Temporarily Linking/Revoking Pseudonym Certificates in VANETs

机译:临时链接/吊销VANET中假名证书的隐私保护方法

获取原文
获取原文并翻译 | 示例

摘要

Vehicular communication (V2X) technologies are expected to become increasingly common in the future. Although they enable improvements on transportation safety and efficiency, the large scale deployment of V2X requires addressing some challenges. In particular, to prevent abuse by drivers and by the system itself, V2X architectures must: (1) ensure the authenticity of messages, which is usually accomplished by means of digital certification; and (2) preserve the privacy of honest users, so owners of non-revoked certificates cannot be easily identified or tracked by eavesdroppers. A promising design to address these requirements is the Security Credential Management System (SCMS), which is currently among the main candidates for protecting V2X communications in the United States. Even though SCMS provides efficient, scalable and privacy-preserving mechanisms for managing V2X-oriented certificates, in this paper we show that it can be further enhanced. Namely, we present two birthday attacks against SCMS's certificate revocation process, both of which degrade the system's security as time passes and more certificates are revoked. We then describe an alternative design to prevent such security degradation with minimal computational overhead. In complement to these security gains, we also describe a mechanism for improving the flexibility of revocation, allowing certificates (as well as their owner's privacy) to be temporarily revoked in an efficient manner. This functionality is useful, for example, to implement suspension mechanisms or to aid in investigations by law-enforcement authorities.
机译:车载通信(V2X)技术有望在未来变得越来越普遍。尽管它们可以提高运输安全性和效率,但V2X的大规模部署仍需要解决一些挑战。特别是,为了防止驱动程序和系统本身滥用,V2X体系结构必须:(1)确保消息的真实性,通常通过数字认证来实现; (2)保留诚实用户的隐私,因此窃听者无法轻松识别或跟踪未吊销证书的所有者。满足这些要求的一种有前途的设计是安全证书管理系统(SCMS),它目前是保护美国V2X通信的主要候选者之一。即使SCMS为管理面向V2X的证书提供了有效,可伸缩且具有隐私保护的机制,但在本文中,我们仍表明可以进一步增强它。即,我们针对SCMS的证书吊销过程提出了两次生日攻击,这两种攻击都会随着时间的流逝而降低系统的安全性,并吊销更多的证书。然后,我们描述一种替代设计,以最小的计算开销防止这种安全性下降。作为对这些安全性的补充,我们还描述了一种提高撤销灵活性的机制,允许以有效方式临时吊销证书(及其所有者的隐私)。例如,此功能可用于实施暂停机制或协助执法机构进行调查。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号