首页> 外文会议>International Conference on Information Systems Security and Privacy >Efficient Authorization Authority Certificate Distribution in VANETs
【24h】

Efficient Authorization Authority Certificate Distribution in VANETs

机译:高效授权机构证书分发兽医

获取原文

摘要

Car-to-X communication systems are about to enter the mass market in upcoming years. Security in these networks depends on digital signatures managed by a multi-level certificate hierarchy. Thereby, certificate distribution is critical in regard to channel utilization and data reception delay via security caused packet loss. These issues are even more significant in case not only pseudonym certificates but also authorization authority certificates have to be exchanged between nodes in the VANET. Prior work has not studied distribution of the elements of a multi-level certificate chain in detail. Hence, this work provides an analysis of the currently standardized mechanisms and identifies several drawbacks of the straight forward solution proposed so far. Thereby, we find a severe denial of service attack on that solution. Moreover, the distribution problem is found to be similar to the packet forwarding problem encountered in position-based routing. Thus, we study several strategies for efficient distribution of a certificate chain in regard to channel load, which are adapted from their counterparts in position-based routing. Thereby, we find that by combining pseudonym certificate buffering with requester based responder selection the requirement for certificate chain distribution in VANETs can be removed completely. Hence, the proposed design avoids the identified denial of service weakness and reduces the worst case size of the security envelope of VANET messages by more than a third.
机译:CAR-TO-X通信系统即将进入即将到来的群众市场。这些网络中的安全性取决于由多级证书层次结构管理的数字签名。由此,证书分布对于信道利用率和数据接收延迟通过安全性引起的分组丢失是至关重要的。这些问题在不仅是假名证书而且还必须在VANET中的节点之间交换授权授权证书。事先工作未详细研究多级证书链的元素。因此,这项工作提供了对目前标准化机制的分析,并识别到目前为止提出的直接解决方案的几个缺点。因此,我们发现对该解决方案的严重拒绝服务攻击。此外,发现分布问题类似于基于位置的路由中遇到的分组转发问题。因此,我们研究了几种策略,以便在信道负载方面有效分布证书链,这与基于位置路由的对应物调整。由此,我们发现,通过基于请求者的响应者选择结合假名证书缓冲,可以完全除去vanet中证书链分布的要求。因此,所提出的设计避免了识别的拒绝服务弱点,并减少了Vanet消息的安全包络的最坏情况大小超过了三分之一。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号