Robust Revocable Anonymous Authentication for Vehicle to Grid Communications

Robust Revocable Anonymous Authentication for Vehicle to Grid Communications
复制标题

DOI:
10.1109/tits.2019.2948803
复制
发表时间:
2020-11
影响因子:
8.5
通讯作者:
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue
中科院分区:
工程技术1区
文献类型:
--
作者:
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue

文献摘要

被引文献

相似文献

电动汽车由于其计划外的充电事件,可能会对电网造成很大的负载。提高电网稳定性的一种方法是提前安排电动汽车充电。在充电访问之前,电动车辆提供必要的信息以请求在充电站充电,充电站在访问之前准备和储备能量。然而,报告的信息可能导致电动车用户的隐私泄露。匿名信息报告可以保护用户隐私,但也会使未经授权的用户对充电站进行攻击。匿名身份验证系统可以解决这些问题,但无法检测已验证用户的不当行为。对此的一种补救措施是基于匿名的身份验证,它可以在恶意用户的错误行为之后撤销其匿名性。然而,我们发现这样的系统仍然容易受到应用级拒绝服务攻击,恶意用户同时从许多充电站请求大量能量,阻止这些充电站为其他用户提供服务。为了解决这个问题,我们改进了现有的基于匿名的身份验证框架。我们提出了一个基于盲签名的机制,每个电动汽车一次只发放一个基于盲签名的许可证。请求只有在包含有效且未使用的许可证时才有效,这可以保护系统免受应用程序级拒绝服务攻击。安全性分析和实验表明,我们的框架,同时确保用户匿名性和上述攻击的鲁棒性,也是可扩展的和轻量级的。
Electric vehicles can place a significant load on the power grid due to their unscheduled charging events. One way of improving power grid stability is to schedule electric vehicle charging in advance. Before a charging visit, the electric vehicle provides necessary information to request for charging at a charging station, which prepares and reserves the energy before the visit. However, the reported information can cause privacy leakage of the electric vehicle user. Anonymous information reporting can protect user privacy, but also enables attacks on the charging station by unauthorized users. An anonymous authentication system can address these issues, but cannot detect misbehaviors by authenticated users. One remedy to this is revocable anonymity-based authentication, which can revoke the anonymity of malicious users after their misbehaviors. However, we show that such a system is still vulnerable to application-level Denial of Service attacks, where a malicious user requests for large amounts of energy simultaneously from many charging stations, preventing these stations from serving other users. To address this, we improve upon an existing revocable anonymity-based authentication framework. We propose a permit-based mechanism, where each electric vehicle is only issued with one blind signature-based permit at a time. A request is valid only if it contains a valid and unused permit, which protects the system from the application-level Denial of Service attacks. Security analysis and experiments demonstrate that our framework, while ensuring user anonymity and being robust to the aforementioned attack, is also scalable and lightweight.