PUCA: A pseudonym scheme with strong privacy guarantees for vehicular ad-hoc networks

PUCA: A pseudonym scheme with strong privacy guarantees for vehicular ad-hoc networks
复制标题

DOI:
10.1016/j.adhoc.2015.09.011
复制
发表时间:
2016-02
期刊:
影响因子:
4.8
通讯作者:
David Förster;F. Kargl;Hans Löhr
David Förster;F. Kargl;Hans Löhr
中科院分区:
计算机科学2区
文献类型:
--
作者:
David Förster;F. Kargl;Hans Löhr

文献摘要

被引文献

相似文献

在车辆自组织网络中,假名证书是安全和隐私友好的消息认证的最先进的方法。然而,大多数拟议的假名计划都侧重于参与者的隐私。后端提供商的隐私通常(如果有的话)只受到责任分离的保护。当实体协作时,例如当需要撤销长期凭证时,可以覆盖保护。这种方法把用户的隐私处于危险之中,如果后端系统不完全trusted.We提出PUCA -一个计划,提供完全匿名的诚实的用户,即使对串通后端供应商。该方案使用匿名凭证与后端进行身份验证,同时保持车辆之间的通信和路边单元不变,并符合现有标准。为了从系统中删除行为不端的车辆,我们利用了一个隐私友好的撤销机制,不需要解析名称。通过我们的方案,我们证明了在车辆网络中可以实现强大的和可验证的隐私保护,同时满足常见的安全要求,如抗sybil和撤销。
Pseudonym certificates are the state-of-the-art approach for secure and privacy-friendly message authentication in vehicular ad-hoc networks. However, most of the proposed pseudonym schemes focus on privacy among participants. Privacy towards backend providers is usually (if at all) only protected by separation of responsibilities. The protection can be overridden, when the entities collaborate, e.g. when revocation of long-term credentials is required. This approach puts the users’ privacy at risk, if the backend systems are not fully trusted.We propose PUCA – a scheme that provides full anonymity for honest users, even against colluding backend providers. The scheme uses anonymous credentials for authentication with the backend, while leaving the communication among vehicles and with road side units unchanged and in compliance with existing standards. For removal of misbehaving vehicles from the system, we leverage a privacy-friendly revocation mechanism, that does not require resolution of pseudonyms. With our scheme, we demonstrate that strong and verifiable privacy protection in vehicular networks can be achieved, while fulfilling common security requirements, such as sybil-resistance and revocation.