Device capture resilient authentication and key agreement protocol for IoV
奇 姜, 雪 杨, 金花 王, 庆丰 程, 鑫迪 马, 建峰 马 · Scientia Sinica Informationis · 2022
With the steady growth of car ownership and the saturation of road traffic, the Internet of vehicle (IoV) is regarded as one of the most effective technologies to improve traffic efficiency and driving experience. Authentication and key agreement protocol (AKA) is a key means to ensure secure interaction between the onboard unit (OBU) and the various information servers. Typically, the private key of AKA protocol is stored in the OBU. However, OBU theft occurs as vehicles are often left unattended. Therefore, it is a challenge to ensure the secure storage of private keys. To address the above problem, a capture-resistant AKA protocol based on oblivious pseudorandom functions (OPRF) and collaborative signature is proposed in this paper. The private key is divided into two parts, one is encrypted using the public key of the auxiliary device and another can only be recovered by running the OPRF protocol between the OBU and the auxiliary device. Since no secret information is stored in the OBU, the adversary cannot obtain the private key even if the OBU is stolen. The comprehensive security analysis and performance comparison of the proposed scheme is provided in this paper. The result demonstrates that the proposed scheme is resistant to various known attacks, especially key leakage caused by device capture. In addition, the proposed scheme can strike a balance between computational and communication overhead.