Cargando…

Zero-knowledge identity authentication for internet of vehicles: Improvement and application

The popularity of Internet of Vehicles (IoV) has made people's driving environment more comfortable and convenient. However, with the integration of external networks and the vehicle networks, the vulnerabilities of the Controller Area Network (CAN) are exposed, allowing attackers to remotely i...

Descripción completa

Detalles Bibliográficos
Autores principales: Han, Mu, Yin, Zhikun, Cheng, Pengzhou, Zhang, Xing, Ma, Shidian
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7521753/
https://www.ncbi.nlm.nih.gov/pubmed/32986720
http://dx.doi.org/10.1371/journal.pone.0239043
_version_ 1783588038363840512
author Han, Mu
Yin, Zhikun
Cheng, Pengzhou
Zhang, Xing
Ma, Shidian
author_facet Han, Mu
Yin, Zhikun
Cheng, Pengzhou
Zhang, Xing
Ma, Shidian
author_sort Han, Mu
collection PubMed
description The popularity of Internet of Vehicles (IoV) has made people's driving environment more comfortable and convenient. However, with the integration of external networks and the vehicle networks, the vulnerabilities of the Controller Area Network (CAN) are exposed, allowing attackers to remotely invade vehicle networks through external devices. Based on the remote attack model for vulnerabilities of the in-vehicle CAN, we designed an efficient and safe identity authentication scheme based on Feige-Fiat-Shamir (FFS) zero-knowledge identification scheme with extremely high soundness. We used the method of zero-one reversal and two-to-one verification to solve the problem that FFS cannot effectively resist guessing attacks. Then, we carried out a theoretical analysis of the scheme’s security and evaluated it on the software and hardware platform. Finally, regarding time overhead, under the same parameters, compared with the existing scheme, the scheme can complete the authentication within 6.1ms without having to go through multiple rounds of interaction, which reduces the additional authentication delay and enables all private keys to participate in one round of authentication, thereby eliminating the possibility that a private key may not be involved in the original protocol. Regarding security and soundness, as long as private keys are not cracked, the scheme can resist guessing attacks, which is more secure than the existing scheme.
format Online
Article
Text
id pubmed-7521753
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-75217532020-10-06 Zero-knowledge identity authentication for internet of vehicles: Improvement and application Han, Mu Yin, Zhikun Cheng, Pengzhou Zhang, Xing Ma, Shidian PLoS One Research Article The popularity of Internet of Vehicles (IoV) has made people's driving environment more comfortable and convenient. However, with the integration of external networks and the vehicle networks, the vulnerabilities of the Controller Area Network (CAN) are exposed, allowing attackers to remotely invade vehicle networks through external devices. Based on the remote attack model for vulnerabilities of the in-vehicle CAN, we designed an efficient and safe identity authentication scheme based on Feige-Fiat-Shamir (FFS) zero-knowledge identification scheme with extremely high soundness. We used the method of zero-one reversal and two-to-one verification to solve the problem that FFS cannot effectively resist guessing attacks. Then, we carried out a theoretical analysis of the scheme’s security and evaluated it on the software and hardware platform. Finally, regarding time overhead, under the same parameters, compared with the existing scheme, the scheme can complete the authentication within 6.1ms without having to go through multiple rounds of interaction, which reduces the additional authentication delay and enables all private keys to participate in one round of authentication, thereby eliminating the possibility that a private key may not be involved in the original protocol. Regarding security and soundness, as long as private keys are not cracked, the scheme can resist guessing attacks, which is more secure than the existing scheme. Public Library of Science 2020-09-28 /pmc/articles/PMC7521753/ /pubmed/32986720 http://dx.doi.org/10.1371/journal.pone.0239043 Text en © 2020 Han et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Han, Mu
Yin, Zhikun
Cheng, Pengzhou
Zhang, Xing
Ma, Shidian
Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title_full Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title_fullStr Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title_full_unstemmed Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title_short Zero-knowledge identity authentication for internet of vehicles: Improvement and application
title_sort zero-knowledge identity authentication for internet of vehicles: improvement and application
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7521753/
https://www.ncbi.nlm.nih.gov/pubmed/32986720
http://dx.doi.org/10.1371/journal.pone.0239043
work_keys_str_mv AT hanmu zeroknowledgeidentityauthenticationforinternetofvehiclesimprovementandapplication
AT yinzhikun zeroknowledgeidentityauthenticationforinternetofvehiclesimprovementandapplication
AT chengpengzhou zeroknowledgeidentityauthenticationforinternetofvehiclesimprovementandapplication
AT zhangxing zeroknowledgeidentityauthenticationforinternetofvehiclesimprovementandapplication
AT mashidian zeroknowledgeidentityauthenticationforinternetofvehiclesimprovementandapplication