Advanced Search
Turn off MathJax
Article Contents
WU Linjun, DING Lin. PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260606
Citation: WU Linjun, DING Lin. PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260606

PUF-driven Secure Anonymous Authentication Protocol for Internet of Vehicles

doi: 10.11999/JEIT260606 cstr: 32379.14.JEIT260606
Funds:  Hunan Natural Science Foundation (2026JJ90049), Scientific Research Fund of Hunan Provincial Education Department (25A0527)
  • Accepted Date: 2026-09-14
  • Rev Recd Date: 2026-09-14
  • Available Online: 2026-09-20
  •   Objective  In the Internet of Vehicles (IoV), vehicles often send Basic Safety Messages through open wireless links to support road safety and traffic control. However, these messages may expose vehicle identity and travel data. An attacker may collect messages over time and link them to the same vehicle. Thus, vehicle authentication must protect both network security and user privacy. Many current anonymous authentication schemes use complex cryptographic operations, which may cause high computation and communication costs for on-board units (OBUs) with limited resources. Some schemes also store long-term secret keys in vehicle devices. Such keys may be exposed by physical access or side-channel attacks. A Physical Unclonable Function (PUF) uses small process changes formed during chip production to create a unique hardware feature. It can produce device-related responses without storing a secret key directly. Based on this feature, this paper proposes a PUF-driven secure anonymous authentication protocol for IoV. The main goal is to reduce the risk of long-term key storage, protect vehicle identity, and keep the cost of vehicle authentication low.  Methods  The proposed protocol uses a response-feedback-based lightweight anti-machine-learning-attack PUF (FLAM-PUF) as its hardware root of trust. FLAM-PUF combines an Arbiter PUF with a reconfigurable Linear Feedback Shift Register (LFSR). The PUF response is fed back to change the LFSR state, which hides the link between Challenge–Response Pairs (CRPs) and makes machine-learning modeling attacks more difficult (Fig. 1). The system includes a Center Management (CM), Local Management entities (LMs), Roadside Units (RSUs), and vehicle OBUs (Fig. 2). During setup, reliable CRPs are collected in a trusted environment and sent to the CM through a secure channel. The main protocol parameters are listed in Table 1. A PUF challenge is used to form a vehicle pseudonym, while its response is used as authentication or session-key data. The OBU can recover the response from its local PUF when needed, so it does not need to store a long-term secret key. The setup process is shown in Fig. 3. The protocol uses two types of pseudonyms. Long-term pseudonyms are used for network access and identity management, while temporary pseudonyms are used for communication within an LM area. The local access process is shown in Fig. 4. Temporary pseudonyms and session keys are updated with unused CRPs (Fig. 5), and long-term pseudonyms are renewed before they expire (Fig. 6). Security is studied under the Dolev–Yao model by using BAN logic, ProVerif formal verification and informal analysis.  Results and Discussions  The proposed protocol combines PUF-based key generation with dynamic pseudonym management. First, FLAM-PUF uses response feedback and a reconfigurable LFSR to hide the internal CRP relation, which raises the cost of machine-learning modeling attacks (Fig. 1). Second, the use of long-term and temporary pseudonyms separates network access from local vehicle communication. CRPs, pseudonyms, and session keys are updated together, which reduces the chance that an attacker can link vehicle identities across different authentication periods (Fig. 4; Fig. 5; Fig. 6). BAN logic analysis shows that the vehicle can confirm the link between the temporary pseudonym and the PUF-based session key, while the LM can confirm that this link is approved by the CM. ProVerif verification shows that the secrecy queries for the vehicle identity and PUF responses hold, and all three injective authentication correspondences are satisfied. Under the assumed freshness and one-time CRP usage conditions, the results also support the protocol's resistance to replay and impersonation attacks. Informal security analysis shows that the protocol supports mutual authentication, anonymity, traceability, revocability, and protocol-level identity unlinkability. It can also resist replay, impersonation, man-in-the-middle, and false-message attacks (Table 3). In addition, the OBU does not need to keep a long-term secret key in nonvolatile memory because the required PUF response can be recovered when needed. This reduces the risk of direct key extraction. For performance tests, the running times of the main cryptographic operations are measured (Table4), and the operations performed by the OBU, CM, and LM in each protocol stage are listed in Table 4. For one complete online authentication and session-key agreement, the OBU computation time of the proposed scheme is about 1365.99 μs, and its communication cost is 992 bits (Table 6). Under the same test rules, its computation time is close to that of Ref. [14] and lower than those of Refs. [15]-[17]. Its communication cost is also lower than those of all four compared schemes. These results show that the protocol can provide more security functions while keeping the vehicle-side cost low.  Conclusions  This paper proposes a PUF-driven secure anonymous authentication protocol for IoV. FLAM-PUF is used as a hardware root of trust to recover authentication and session-key data when needed, so long-term secret keys do not need to be stored directly in the OBU. The use of long-term and temporary pseudonyms supports anonymous access, identity tracing, revocation, and protocol-level unlinkability. BAN logic, ProVerif formal verification, and informal security analysis show that the protocol meets its main security goals and can resist common network attacks. Performance results show that one online authentication and session-key agreement needs about 1365.99 μs of OBU computation and 992 bits of communication (Table 6). The proposed protocol therefore provides a useful balance among security, privacy, and low cost, and is suitable for resource-limited IoV devices.
  • loading
  • [1]
    CVE. 特斯拉TCU<v2025.14认证绕过漏洞[EB/OL]. https://cve.imfht.com/detail/CVE-2025-34251, 2026. (查阅网上资料,未找到对应的英文翻译,请补充).
    [2]
    张晓均, 唐浩宇, 张楠, 等. 分布式智能车载网联系统的匿名认证与密钥协商协议[J]. 电子与信息学报, 2024, 46(4): 1333–1342. doi: 10.11999/JEIT230394.

    ZHANG Xiaojun, TANG Haoyu, ZHANG Nan, et al. Anonymous authentication and key agreement protocol based on distributed intelligent vehicle networking system[J]. Journal of Electronics & Information Technology, 2024, 46(4): 1333–1342. doi: 10.11999/JEIT230394.
    [3]
    张应辉, 李国腾, 韩刚, 等. 5G车联网中安全高效的组播服务认证与密钥协商方案[J]. 电子与信息学报, 2024, 46(7): 3026–3035. doi: 10.11999/JEIT231118.

    ZHANG Yinghui, LI Guoteng, HAN Gang, et al. Secure and efficient authentication and key agreement scheme for multicast services in 5G vehicular to everything[J]. Journal of Electronics & Information Technology, 2024, 46(7): 3026–3035. doi: 10.11999/JEIT231118.
    [4]
    MANASRAH A, YASEEN Q, AL-AQRABI H, et al. Identity-based authentication in VANETs: A review[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(4): 4260–4282. doi: 10.1109/TITS.2025.3528932.
    [5]
    VERMA G K, RANA S, TIWARI A, et al. Dynamic anonymous hierarchical edge-assisted batch verifiable authentication for VANETs[J]. IEEE Transactions on Vehicular Technology, 2025, 74(9): 14735–14744. doi: 10.1109/TVT.2025.3566415.
    [6]
    WANG Yahui, JIA Xiaoying, BAO Yingying, et al. Efficient and provably secure offline/online heterogeneous signcryption scheme for VANETs[J]. IEEE Internet of Things Journal, 2024, 11(24): 41248–41260. doi: 10.1109/JIOT.2024.3458077.
    [7]
    LI Kang, AU M H, HO W H, et al. An efficient conditional privacy-preserving authentication scheme for vehicular ad hoc networks using online/offline certificateless aggregate signature[C]. Proceedings of the 13th International Conference on Provable Security, Cairns, Australia, 2019: 59–76. doi: 10.1007/978-3-030-31919-9_4.
    [8]
    ZHOU Ziyu, WANG Pengjun, LI Gang, et al. Improving the stability of APUF to 100% without extra hardware overhead for enhancing the performance of security authentication protocols[J]. IEEE Internet of Things Journal, 2025, 12(12): 19818–19832. doi: 10.1109/JIOT.2025.3541434.
    [9]
    NI Li, WU Siyuan, PU Jinwei, et al. Highly reliable RRAM-based physical unclonable function with auto-write technique[J]. IEEE Transactions on Very Large Scale Integration (VLSI) Systems, 2026, 34(6): 2000–2004. doi: 10.1109/TVLSI.2026.3670888.
    [10]
    WU Linjun, HU Yupeng, ZHANG Kehuan, et al. FLAM-PUF: A response–feedback-based lightweight anti-machine-learning-attack PUF[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2022, 41(11): 4433–4444. doi: 10.1109/TCAD.2022.3197696.
    [11]
    CHOI J, KWON D, SON S, et al. A PUF-based lightweight authentication scheme for UAV-assisted internet of vehicles[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(9): 13782–13798. doi: 10.1109/TITS.2025.3564581.
    [12]
    JIA Chunzhi, TAN Weijie, SHEN Ao, et al. A PUF-enhanced fog-enabled hierarchical authentication protocol for internet of vehicles[J]. IEEE Internet of Things Journal, 2025, 12(18): 37629–37644. doi: 10.1109/JIOT.2025.3583822.
    [13]
    SHEN Ao, TAN Weijie, JIA Chunzhi, et al. CUBE-PUF-based anonymous mutual authentication protocol for internet of vehicles[J]. IEEE Internet of Things Journal, 2025, 12(18): 38697–38709. doi: 10.1109/JIOT.2025.3586869.
    [14]
    LI Jiping, CHEN Jing, LIU Yining, et al. An efficient and revocable PUF-based authentication scheme for secure V2R mutual communication in VANETs[J]. IEEE Internet of Things Journal, 2025, 12(18): 37974–37987. doi: 10.1109/JIOT.2025.3585643.
    [15]
    夏卓群, 苏潮, 徐梓桑, 等. 基于物理不可克隆函数的轻量级可证明安全车联网认证协议[J]. 电子与信息学报, 2024, 46(9): 3788–3796. doi: 10.11999/JEIT240141.

    XIA Zhuoqun, SU Chao, XU Zisang, et al. A lightweight and provably secure authentication protocol for internet of vehicles using physical unclonable function[J]. Journal of Electronics & Information Technology, 2024, 46(9): 3788–3796. doi: 10.11999/JEIT240141.
    [16]
    VIJAYAKUMAR P, RAJASEKARAN A S, AZEES M, et al. Probably secure PUF-based anonymous mutual and batch authentication for inter-vehicular communications in VANET[J]. IEEE Transactions on Vehicular Technology, 2026, 75(2): 2516–2526. doi: 10.1109/TVT.2025.3600097.
    [17]
    YANG Yuting, TAN Weijie, LI Zhen, et al. Mutual authentication protocols based on PUF and multitrusted authority for internet of vehicles[J]. IEEE Internet of Things Journal, 2024, 11(24): 40086–40099. doi: 10.1109/JIOT.2024.3449901.
    [18]
    CHAUHDARY S H, MA Tengfei, JIANG Linhua, et al. PUF-ILM: A PUF-enabled authentication scheme for internet of vehicles using improved logical mapping[J]. IEEE Internet of Things Journal, 2026, 13(7): 13787–13800. doi: 10.1109/JIOT.2026.3656432.
    [19]
    ZHOU Ziyu, LI Gang, ZHANG Yuejun, et al. A strong PUF-based security protocol to protect AI model parameters against privacy information leakage[J]. IEEE Internet of Things Journal, 2025, 12(12): 20815–20827. doi: 10.1109/JIOT.2025.3544555.
    [20]
    XIE Yuanfeng, JIANG Weiwei, LUO Hanqing, et al. A lightweight and efficient authentication protocol based on AST PUF and Schnorr for IoT[J]. IEEE Internet of Things Journal, 2026, 13(1): 1606–1621. doi: 10.1109/JIOT.2025.3629693.
    [21]
    DOLEV D and YAO A. On the security of public key protocols[J]. IEEE Transactions on Information Theory, 1983, 29(2): 198–208. doi: 10.1109/TIT.1983.1056650.
    [22]
    BLANCHET B. An efficient cryptographic protocol verifier based on Prolog rules[C]. Proceedings of the 14th IEEE Computer Security Foundations Workshop, Cape Breton, Canada, 2001: 82–96. doi: 10.1109/CSFW.2001.930138.
  • 加载中

Catalog

    通讯作者: 陈斌, bchen63@163.com
    • 1. 

      沈阳化工大学材料科学与工程学院 沈阳 110142

    1. 本站搜索
    2. 百度学术搜索
    3. 万方数据库搜索
    4. CNKI搜索

    Figures(6)  / Tables(6)

    Article Metrics

    Article views (21) PDF downloads(0) Cited by()
    Proportional views
    Related

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return