In recent years, the Institute of Electrical and Electronics Engineers (IEEE) and the European Telecommunications Standards Institute (ETSI) have developed a series of security communication standards for vehicular communications. These standards include mechanisms such as the Security Credential Management System (SCMS) and Butterfly Key Expansion (BKE) to protect vehicle privacy. However, these standards are mainly based on the Elliptic-Curve Cryptography (ECC), which may be vulnerable to attacks from quantum computing in the future. In response to this potential risk, this study proposes a hybrid certificate that combines the ECC with Post-Quantum Cryptography (PQC). This approach enables infrastructure systems to be built on cryptographic foundations that are more resilient to quantum-based attacks. Furthermore, this study presents a generalized pseudonym scheme that is compatible with various cryptographic algorithms for generating pseudonym certificates. This design aims to eliminate the possibility of inferring any correlation between the public key in a pseudonym certificate and that in an enrollment certificate. This study also conducts a comprehensive performance evaluation of the RSA, ECC, and PQC algorithms, particularly those standardized by the National Institute of Standards and Technology (NIST). The comparison considers factors such as message length and computation time. Based on the findings, this study recommends suitable pseudonym schemes that adopt hybrid certificates for secure and efficient use in vehicular communications.
翻译:近年来,电气与电子工程师协会(IEEE)和欧洲电信标准化协会(ETSI)制定了一系列车载通信安全通信标准。这些标准包含安全凭证管理系统(SCMS)和蝴蝶密钥扩展(BKE)等机制,以保护车辆隐私。然而,这些标准主要基于椭圆曲线密码学(ECC),未来可能面临量子计算攻击的威胁。针对这一潜在风险,本研究提出了一种结合ECC与后量子密码学(PQC)的混合证书。该方法使基础设施系统能够构建在更能抵御量子攻击的密码学基础上。此外,本研究提出了一种通用的假名方案,该方案兼容多种生成假名证书的密码算法。该设计旨在消除通过假名证书中的公钥与注册证书中的公钥推断其关联的可能性。本研究还对RSA、ECC和PQC算法(特别是美国国家标准与技术研究院(NIST)标准化后的算法)进行了全面的性能评估,综合考虑了消息长度和计算时间等因素。基于研究结果,本研究推荐了适用于车载通信中安全高效应用的采用混合证书的假名方案。