首页> 外文期刊>PLoS One >Zero-knowledge identity authentication for internet of vehicles: Improvement and application
【24h】

Zero-knowledge identity authentication for internet of vehicles: Improvement and application

机译:用于车辆互联网的零知识身份认证:改进和应用

获取原文
       

摘要

The popularity of Internet of Vehicles (IoV) has made people's driving environment more comfortable and convenient. However, with the integration of external networks and the vehicle networks, the vulnerabilities of the Controller Area Network (CAN) are exposed, allowing attackers to remotely invade vehicle networks through external devices. Based on the remote attack model for vulnerabilities of the in-vehicle CAN, we designed an efficient and safe identity authentication scheme based on Feige-Fiat-Shamir (FFS) zero-knowledge identification scheme with extremely high soundness. We used the method of zero-one reversal and two-to-one verification to solve the problem that FFS cannot effectively resist guessing attacks. Then, we carried out a theoretical analysis of the scheme’s security and evaluated it on the software and hardware platform. Finally, regarding time overhead, under the same parameters, compared with the existing scheme, the scheme can complete the authentication within 6.1ms without having to go through multiple rounds of interaction, which reduces the additional authentication delay and enables all private keys to participate in one round of authentication, thereby eliminating the possibility that a private key may not be involved in the original protocol. Regarding security and soundness, as long as private keys are not cracked, the scheme can resist guessing attacks, which is more secure than the existing scheme.
机译:车辆互联网的普及(IOV)使人们的驾驶环境更舒适,方便。然而,随着外部网络和车辆网络的集成,控制器区域网络(CAN)的漏洞被暴露,允许攻击者通过外部设备远程侵入车辆网络。基于车载漏洞的漏洞攻击模型,我们设计了一种基于Feige-Fiat-Shamir(FFS)零知识识别方案的高效和安全的身份认证方案,具有极高的声音。我们使用了零一个逆转和双到一对一验证的方法来解决FF不能有效地抵抗猜测攻击的问题。然后,我们对该方案的安全性进行了理论分析,并在软件和硬件平台上进行了评估。最后,关于时间开销,与现有方案相同的参数,该方案可以在6.1ms内完成身份验证,而无需多轮交互,这减少了额外的身份验证延迟并启用所有私钥参与一轮认证,从而消除了私钥可能不参与原始协议的可能性。关于安全性和声音,只要私钥没有破裂,该方案就可以抵抗猜测攻击,这比现有方案更安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号