An Improved Cross-Layer Privacy-Preserving Authentication in WAVE-Enabled VANETs
Title | An Improved Cross-Layer Privacy-Preserving Authentication in WAVE-Enabled VANETs |
Publication Type | Journal Article |
Year of Publication | 2014 |
Authors | Jia-Lun Tsai |
Journal | Communications Letters, IEEE |
Volume | 18 |
Pagination | 1931-1934 |
Date Published | Nov |
ISSN | 1089-7798 |
Keywords | authentication, authentication scheme, data privacy, digital signatures, ECDSA, elliptic curve digital signature algorithm, elliptic curve digital signature algorithm (ECDSA), Elliptic curves, identity revocation, identity trace, improved cross-layer privacy-preserving authentication scheme, Law, legal signing vehicle, malicious receiving vehicle, Privacy-preserving, private key cryptography, private key reveal attack, Public key, public key cryptography, receiving entity, security analysis, security strength evaluation, telecommunication security, valid signature, VANETs, Vehicles, vehicular ad hoc networks, WAVE-based vehicular ad hoc networks, WAVE-enabled VANET |
Abstract | In 2013, Biswas and Misic proposed a new privacy-preserving authentication scheme for WAVE-based vehicular ad hoc networks (VANETs), claiming that they used a variant of the Elliptic Curve Digital Signature Algorithm (ECDSA). However, our study has discovered that the authentication scheme proposed by them is vulnerable to a private key reveal attack. Any malicious receiving vehicle who receives a valid signature from a legal signing vehicle can gain access to the signing vehicle private key from the learned valid signature. Hence, the authentication scheme proposed by Biswas and Misic is insecure. We thus propose an improved version to overcome this weakness. The proposed improved scheme also supports identity revocation and trace. Based on this security property, the CA and a receiving entity (RSU or OBU) can check whether a received signature has been generated by a revoked vehicle. Security analysis is also conducted to evaluate the security strength of the proposed authentication scheme. |
URL | https://ieeexplore.ieee.org/document/6814798 |
DOI | 10.1109/LCOMM.2014.2323291 |
Citation Key | 6814798 |
- Privacy-preserving
- WAVE-enabled VANET
- WAVE-based vehicular ad hoc networks
- vehicular ad hoc networks
- vehicles
- VANETs
- valid signature
- telecommunication security
- security strength evaluation
- Security analysis
- receiving entity
- public key cryptography
- Public key
- private key reveal attack
- private key cryptography
- authentication
- malicious receiving vehicle
- legal signing vehicle
- Law
- improved cross-layer privacy-preserving authentication scheme
- identity trace
- identity revocation
- Elliptic curves
- elliptic curve digital signature algorithm (ECDSA)
- elliptic curve digital signature algorithm
- ECDSA
- digital signatures
- data privacy
- authentication scheme