高级搜索

留言板

尊敬的读者、作者、审稿人, 关于本刊的投稿、审稿、编辑和出版的任何问题, 您可以本页添加留言。我们将尽快给您答复。谢谢您的支持!

姓名
邮箱
手机号码
标题
留言内容
验证码

面向车联网的PUF驱动安全匿名认证协议

伍麟珺 丁林

伍麟珺, 丁林. 面向车联网的PUF驱动安全匿名认证协议[J]. 电子与信息学报. doi: 10.11999/JEIT260606
引用本文: 伍麟珺, 丁林. 面向车联网的PUF驱动安全匿名认证协议[J]. 电子与信息学报. doi: 10.11999/JEIT260606
WU Linjun, DING Lin. PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260606
Citation: WU Linjun, DING Lin. PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260606

面向车联网的PUF驱动安全匿名认证协议

doi: 10.11999/JEIT260606 cstr: 32379.14.JEIT260606
基金项目: 湖南省自然科学基金(2026JJ90049),湖南省教育厅科学研究项目(25A0527)
详细信息
    作者简介:

    伍麟珺:女,讲师,研究方向为硬件安全、信息安全、智能通信

    丁林:男,助理研究员,研究方向为硬件安全、密码芯片、隐私保护计算

    通讯作者:

    丁林 dinglin@pku.edu.cn

  • 中图分类号: TP

PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles

Funds: Hunan Natural Science Foundation (2026JJ90049), Scientific Research Fund of Hunan Provincial Education Department (25A0527)
  • 摘要: 车联网作为智能交通系统的重要组成部分,通过车车与车路信息交互提升交通运行效率,正逐步成为智慧城市建设的重要基础设施。车联网车辆通过周期性广播基本安全消息辅助协同感知与智能决策,但明文传输可能导致车辆身份和行驶轨迹泄露。针对现有匿名认证方案中计算与通信开销较高,以及长期密钥存储易受到物理提取和侧信道攻击等问题,本文提出一种面向车联网的物理不可克隆函数(Physical Unclonable Function, PUF)驱动安全匿名认证协议。该协议利用集成电路制造过程中形成的随机工艺偏差构建设备相关硬件指纹,并基于PUF激励–响应机制生成会话密钥,结合激励信息构造和更新车辆伪名。本方案利用PUF固有的物理不可克隆特性增强认证安全性,并结合密码学机制实现无需片内存储长期敏感密钥的硬件辅助认证,从而降低物理提取和侧信道攻击导致的密钥泄漏风险。在Dolev–Yao攻击模型下,本文采用BAN逻辑、ProVerif形式化验证和非形式化方法对协议安全性进行分析。分析结果表明,所提方案能够抵御重放攻击、伪装攻击和中间人攻击,并满足匿名性、可追溯性以及协议层身份不可链接性等安全需求。性能分析结果表明,所提方案在保证多项安全功能的同时具有较低的计算与通信开销,适用于资源受限的车联网环境。
  • 图  1  (a)FLAM-PUF结构 图1(b)FLAM-PUF 响应反馈流程

    图  2  车辆伪名管理分发机制系统架构图

    图  3  初始化时序图

    图  4  本地入网认证时序图

    图  5  临时伪名更新时序图

    图  6  长期伪名更新时序图

    表  1  伪名管理方案参数表

    符号描述符号描述
    Vh第h辆车PKc中心管理局CM公钥
    CM中心管理局SKc中心管理局CM私钥
    LMi第i个本地管理局CRPPUF的激励响应对集合
    RSU路侧单元crpx第x个激励响应对
    rid车辆全网唯一永久标识chxcrpx的激励
    lid车辆长期伪名resxcrpx的响应
    pid车辆临时伪名Enckey{}以key为密钥的加密操作
    Kch车辆Vh与中心管理局CM之间基于PUF响应建立的认证密钥Deckey{}以key为密钥的解密操作
    Kih车辆Vh与本地管理局LMi之间的共享会话密钥stamp时间戳
    LPK本地管理局LM公钥r随机数
    LSK本地管理局LM私钥time伪名或者密钥使用有效期
    下载: 导出CSV

    表  2  ProVerif安全查询及验证结果

    验证目标 ProVerif查询/对应关系 验证结果
    永久身份机密性 query attacker(rid) 成立
    当前PUF响应及
    认证密钥机密性
    query attacker(res1) 成立
    新PUF响应及会话
    密钥机密性
    query attacker(res2) 成立
    CM对车辆的认证 CM接受$\Rightarrow $车辆发起 注入对应关系成立
    车辆对CM的认证 车辆接受$\Rightarrow $CM生成M2 注入对应关系成立
    LMi对CM的认证 LM接受$\Rightarrow $CM生成
    并签署M3
    注入对应关系成立
    下载: 导出CSV

    表  3  认证方案安全属性比较

    安全属性文献[14]文献[15]文献[16]文献[17]本文方案
    双向认证××
    匿名性
    可追溯性××
    可撤销性××
    身份不可链接性×
    抗伪装攻击
    抗重放攻击
    抗中间人攻击
    虚假消息攻击
    无需长期存储密钥(认证参数)××××
    抗建模攻击××
    注释:"√"表示具备相应安全属性或功能,"×"表示不具备相应安全属性或功能。
    下载: 导出CSV

    表  4  密码学操作运行时间

    符号定义运行时间/μs符号定义运行时间/μs
    TP物理不可克隆函数(PUF)682TAD非对称解密25282
    Th哈希函数0.172TEM椭圆曲线点乘1996
    TE对称加密0.947TEA椭圆曲线点加85.486
    TD对称解密0.699TX按位异或9.38
    TSigRSA数字签名生成2183.71TVerRSA数字签名验证410.09
    TAE非对称加密27122TF模糊提取493.63
    下载: 导出CSV

    表  5  各阶段各实体计算运行情况

    认证阶段计算实体计算开销
    本地入网请求车辆OBU2TP+2Th+TE+TD
    中心管理局CM2Th+2TE+TD+3TAE+TSig
    本地管理局LM3TAD+TVer
    临时伪名更新车辆OBUTP+TD+Th
    中心管理局CMTVer+Th+TE+TAE+TSig
    本地管理局LMTVer+TAE+TSig
    长期伪名更新车辆OBU2TP+2Th+TE+TD
    中心管理局CM2Th+TE+TD
    下载: 导出CSV

    表  6  OBU侧计算时延开销与通信开销比较

    安全协议
    方案
    OBU认证计算时延开销μsOBU认证
    通信开销bit
    文献[14]2TP +5TX+5Th1411.761088
    文献[15]2TEM+3Th+TE+TD3994.161664
    文献[16]6TEM+2TEA+6Th+TX+TP+TF13333.013584
    文献[17]2TP+3Th+TF+TE1859.091008
    本文方案2TP+2Th+TE+TD1365.99992
    注释:表中开销均按车辆OBU完成一次在线认证与会话密钥协商统计;计算时延仅计OBU侧密码学操作,通信开销为OBU发送与接收的认证消息总长度,不含注册阶段、其他实体计算及认证后的业务数据。
    下载: 导出CSV
  • [1] CVE. 特斯拉TCU<v2025.14认证绕过漏洞[EB/OL]. https://cve.imfht.com/detail/CVE-2025-34251, 2026. (查阅网上资料,未找到对应的英文翻译,请补充).
    [2] 张晓均, 唐浩宇, 张楠, 等. 分布式智能车载网联系统的匿名认证与密钥协商协议[J]. 电子与信息学报, 2024, 46(4): 1333–1342. doi: 10.11999/JEIT230394.

    ZHANG Xiaojun, TANG Haoyu, ZHANG Nan, et al. Anonymous authentication and key agreement protocol based on distributed intelligent vehicle networking system[J]. Journal of Electronics & Information Technology, 2024, 46(4): 1333–1342. doi: 10.11999/JEIT230394.
    [3] 张应辉, 李国腾, 韩刚, 等. 5G车联网中安全高效的组播服务认证与密钥协商方案[J]. 电子与信息学报, 2024, 46(7): 3026–3035. doi: 10.11999/JEIT231118.

    ZHANG Yinghui, LI Guoteng, HAN Gang, et al. Secure and efficient authentication and key agreement scheme for multicast services in 5G vehicular to everything[J]. Journal of Electronics & Information Technology, 2024, 46(7): 3026–3035. doi: 10.11999/JEIT231118.
    [4] MANASRAH A, YASEEN Q, AL-AQRABI H, et al. Identity-based authentication in VANETs: A review[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(4): 4260–4282. doi: 10.1109/TITS.2025.3528932.
    [5] VERMA G K, RANA S, TIWARI A, et al. Dynamic anonymous hierarchical edge-assisted batch verifiable authentication for VANETs[J]. IEEE Transactions on Vehicular Technology, 2025, 74(9): 14735–14744. doi: 10.1109/TVT.2025.3566415.
    [6] WANG Yahui, JIA Xiaoying, BAO Yingying, et al. Efficient and provably secure offline/online heterogeneous signcryption scheme for VANETs[J]. IEEE Internet of Things Journal, 2024, 11(24): 41248–41260. doi: 10.1109/JIOT.2024.3458077.
    [7] LI Kang, AU M H, HO W H, et al. An efficient conditional privacy-preserving authentication scheme for vehicular ad hoc networks using online/offline certificateless aggregate signature[C]. Proceedings of the 13th International Conference on Provable Security, Cairns, Australia, 2019: 59–76. doi: 10.1007/978-3-030-31919-9_4.
    [8] ZHOU Ziyu, WANG Pengjun, LI Gang, et al. Improving the stability of APUF to 100% without extra hardware overhead for enhancing the performance of security authentication protocols[J]. IEEE Internet of Things Journal, 2025, 12(12): 19818–19832. doi: 10.1109/JIOT.2025.3541434.
    [9] NI Li, WU Siyuan, PU Jinwei, et al. Highly reliable RRAM-based physical unclonable function with auto-write technique[J]. IEEE Transactions on Very Large Scale Integration (VLSI) Systems, 2026, 34(6): 2000–2004. doi: 10.1109/TVLSI.2026.3670888.
    [10] WU Linjun, HU Yupeng, ZHANG Kehuan, et al. FLAM-PUF: A response–feedback-based lightweight anti-machine-learning-attack PUF[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2022, 41(11): 4433–4444. doi: 10.1109/TCAD.2022.3197696.
    [11] CHOI J, KWON D, SON S, et al. A PUF-based lightweight authentication scheme for UAV-assisted internet of vehicles[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(9): 13782–13798. doi: 10.1109/TITS.2025.3564581.
    [12] JIA Chunzhi, TAN Weijie, SHEN Ao, et al. A PUF-enhanced fog-enabled hierarchical authentication protocol for internet of vehicles[J]. IEEE Internet of Things Journal, 2025, 12(18): 37629–37644. doi: 10.1109/JIOT.2025.3583822.
    [13] SHEN Ao, TAN Weijie, JIA Chunzhi, et al. CUBE-PUF-based anonymous mutual authentication protocol for internet of vehicles[J]. IEEE Internet of Things Journal, 2025, 12(18): 38697–38709. doi: 10.1109/JIOT.2025.3586869.
    [14] LI Jiping, CHEN Jing, LIU Yining, et al. An efficient and revocable PUF-based authentication scheme for secure V2R mutual communication in VANETs[J]. IEEE Internet of Things Journal, 2025, 12(18): 37974–37987. doi: 10.1109/JIOT.2025.3585643.
    [15] 夏卓群, 苏潮, 徐梓桑, 等. 基于物理不可克隆函数的轻量级可证明安全车联网认证协议[J]. 电子与信息学报, 2024, 46(9): 3788–3796. doi: 10.11999/JEIT240141.

    XIA Zhuoqun, SU Chao, XU Zisang, et al. A lightweight and provably secure authentication protocol for internet of vehicles using physical unclonable function[J]. Journal of Electronics & Information Technology, 2024, 46(9): 3788–3796. doi: 10.11999/JEIT240141.
    [16] VIJAYAKUMAR P, RAJASEKARAN A S, AZEES M, et al. Probably secure PUF-based anonymous mutual and batch authentication for inter-vehicular communications in VANET[J]. IEEE Transactions on Vehicular Technology, 2026, 75(2): 2516–2526. doi: 10.1109/TVT.2025.3600097.
    [17] YANG Yuting, TAN Weijie, LI Zhen, et al. Mutual authentication protocols based on PUF and multitrusted authority for internet of vehicles[J]. IEEE Internet of Things Journal, 2024, 11(24): 40086–40099. doi: 10.1109/JIOT.2024.3449901.
    [18] CHAUHDARY S H, MA Tengfei, JIANG Linhua, et al. PUF-ILM: A PUF-enabled authentication scheme for internet of vehicles using improved logical mapping[J]. IEEE Internet of Things Journal, 2026, 13(7): 13787–13800. doi: 10.1109/JIOT.2026.3656432.
    [19] ZHOU Ziyu, LI Gang, ZHANG Yuejun, et al. A strong PUF-based security protocol to protect AI model parameters against privacy information leakage[J]. IEEE Internet of Things Journal, 2025, 12(12): 20815–20827. doi: 10.1109/JIOT.2025.3544555.
    [20] XIE Yuanfeng, JIANG Weiwei, LUO Hanqing, et al. A lightweight and efficient authentication protocol based on AST PUF and Schnorr for IoT[J]. IEEE Internet of Things Journal, 2026, 13(1): 1606–1621. doi: 10.1109/JIOT.2025.3629693.
    [21] DOLEV D and YAO A. On the security of public key protocols[J]. IEEE Transactions on Information Theory, 1983, 29(2): 198–208. doi: 10.1109/TIT.1983.1056650.
    [22] BLANCHET B. An efficient cryptographic protocol verifier based on Prolog rules[C]. Proceedings of the 14th IEEE Computer Security Foundations Workshop, Cape Breton, Canada, 2001: 82–96. doi: 10.1109/CSFW.2001.930138.
  • 加载中
图(6) / 表(6)
计量
  • 文章访问数:  21
  • HTML全文浏览量:  4
  • PDF下载量:  0
  • 被引次数: 0
出版历程
  • 修回日期:  2026-09-14
  • 录用日期:  2026-09-14
  • 网络出版日期:  2026-09-20

目录

    /

    返回文章
    返回