The Internet of Vehicles (IoV) can significantly improve transportation efficiency and ensure traffic safety. Authentication is regarded as the fundamental defense line against attacks in IoV. However, the state-of-the-art approaches suffer from several drawbacks, including bottlenecks of the single cloud server model, high computational overhead of operations, excessive trust in cloud servers and roadside units (RSUs), and leakage of vehicle trajectory privacy. In this paper, BEPHAP, a Blockchain-based Efficient Privacy-preserving Handover Authentication Protocol with key agreement for internet of vehicles, is introduced to address these problems. BEPHAP achieves anonymous cross-domain mutual handover authentication with key agreement based on the tamper-proof blockchain, symmetric cryptography, and the chameleon hash function under a security model that cloud servers and RSUs may launch attacks. BEPHAP is particularly well suited for IoV since it allows vehicles only need to perform lightweight cryptographic operations during the authentication phase. BEPHAP also achieves data confidentiality, unlinkability, traceability, non-repudiation, non-frameability, and key escrow freeness. Formal verification based on ProVerif and formal security proofs based on the BAN logic indicates that BEPHAP is resistant to various typical attacks, such as man-in-the-middle attacks, impersonation attacks, and replay attacks. Performance analysis demonstrates that BEPHAP surpasses existing works in both computation and communication efficiencies. And the message loss rate remains 0 at 5000 requests per second, which meets the requirement of IoV.
翻译:车辆互联网(IoV)可以大大提高运输效率和确保交通安全。认证被视为防范IoV攻击的基本防线。然而,最新办法存在若干缺陷,包括单一云端服务器模式的瓶颈、高计算成本、对云端服务器和路边装置的过度信任以及车辆轨迹隐私的泄漏。在本论文中,BEPHAP(基于链的高效私隐保护传输授权协议)与车辆互联网的关键协议一道,被引入了解决这些问题的基本防线。BEPHAP(BEPHAP)实现了匿名跨场互交接认证,而关键协议基于防篡改的路障链、对称加密加密加密的加密仪,沙米隆在云端服务器和路边装置可能发动攻击的安全模式下起作用。BEPHAP(BPHAP)特别适合IoV,因为它只允许车辆在认证阶段进行轻量的加密操作。BEPHAP(BHAP)还实现了数据保密性、不连接性、非校正校准性、非框架性、对标准性攻击的准确性攻击和关键代管性攻击(BEPA)的常规核查。