论文标题

可扩展和弹性的以车辆为中心的证书撤销清单分布在车辆通信系统中

Scalable & Resilient Vehicle-Centric Certificate Revocation List Distribution in Vehicular Communication Systems

论文作者

Khodaei, Mohammad, Papadimitratos, Panos

论文摘要

尽管在确保车辆通信(VC)系统方面取得了进展,但如何分发证书吊销清单(CRL)尚无共识。主要的挑战完全在于(i)(i)为众多匿名凭证,假名,(ii)在撤销事件之前对车辆保持强大的隐私,即使诚实但持续的系统实体(III)(iii)以及符合计算和沟通约束与Intermittive intermentents in Intermittive in Infrastitive in Infrasstornitive in Infrassitive,依靠同行分发CRL是一把双刃剑:虐待的同龄人可以“污染”该过程,从而降低及时的CRLS分布。在本文中,我们提出了一种以车辆为中心的解决方案,该解决方案解决了所有这些挑战,从而缩小了文献中的差距。我们的方案从根本上降低了CRL分布开销:每辆车辆仅接收CRL,仅对应于其操作区域及其实际行程持续时间。此外,CRL'零件'的“指纹”附着在(可验证的)假名的子集上,用于快速CRL“零件”验证(同时减轻资源耗竭攻击滥用CRL分布)。我们的实验评估表明,我们的方案是有效的,可扩展的,可靠的和实用的:在交通负荷的不超过25 kb/s的情况下,最新的CRL可以在15s(15 x 15 km)内(15 x 15 km)内的95%的车辆(即,比州立大学都要快40倍以上。总体而言,我们的计划是一个综合解决方案,可以补充标准,并可以促进安全和隐私保护VC系统的部署。

In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute Certificate Revocation Lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (15 x 15 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源