首页> 外文期刊>IEEE Transactions on Intelligent Transportation Systems >Robust Revocable Anonymous Authentication for Vehicle to Grid Communications
【24h】

Robust Revocable Anonymous Authentication for Vehicle to Grid Communications

机译:用于网格通信的车辆的强大可撤销匿名认证

获取原文
获取原文并翻译 | 示例
       

摘要

Electric vehicles can place a significant load on the power grid due to their unscheduled charging events. One way of improving power grid stability is to schedule electric vehicle charging in advance. Before a charging visit, the electric vehicle provides necessary information to request for charging at a charging station, which prepares and reserves the energy before the visit. However, the reported information can cause privacy leakage of the electric vehicle user. Anonymous information reporting can protect user privacy, but also enables attacks on the charging station by unauthorized users. An anonymous authentication system can address these issues, but cannot detect misbehaviors by authenticated users. One remedy to this is revocable anonymity-based authentication, which can revoke the anonymity of malicious users after their misbehaviors. However, we show that such a system is still vulnerable to application-level Denial of Service attacks, where a malicious user requests for large amounts of energy simultaneously from many charging stations, preventing these stations from serving other users. To address this, we improve upon an existing revocable anonymity-based authentication framework. We propose a permit-based mechanism, where each electric vehicle is only issued with one blind signature-based permit at a time. A request is valid only if it contains a valid and unused permit, which protects the system from the application-level Denial of Service attacks. Security analysis and experiments demonstrate that our framework, while ensuring user anonymity and being robust to the aforementioned attack, is also scalable and lightweight.
机译:由于其未调度的充电事件,电动车辆可以对电网进行显着负载。提高电网稳定性的一种方法是预先安排电动车辆充电。在收费访问之前,电动车辆提供必要的信息,以要求在充电站充电,这在访问前准备和保留能量。然而,报告的信息可能导致电动车辆的隐私泄漏。匿名信息报告可以保护用户隐私,但也可以通过未经授权的用户攻击充电站。匿名身份验证系统可以解决这些问题,但无法通过经过身份验证的用户检测不当行为。一个补救措施是可撤销基于匿名的身份验证,它可以在行为不端的行为之后撤消恶意用户的匿名性。但是,我们表明,这种系统仍然容易受到应用程序级别的拒绝服务攻击,其中恶意用户从许多充电站同时对大量能量请求,防止这些站服务于其他用户。要解决此问题,我们改进了现有的基于匿名的身份验证框架。我们提出了一种基于许可的机制,其中每辆电动车辆一次仅以一种盲目签名的许可证发布。只有当它包含有效和未使用的许可证时,请求才有效,这些许可证可保护系统从应用程序级别拒绝服务攻击。安全性分析和实验表明我们的框架,同时确保用户匿名和对上述攻击的强大,也是可扩展和重量轻的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号