DOI QR코드

DOI QR Code

Certificate Revocation Scheme based on the Blockchain for Vehicular Communications

  • Kim, Hyun-Gon (Dept. of Information Security, Mokpo National University)
  • Received : 2020.06.11
  • Accepted : 2020.07.20
  • Published : 2020.07.31

Abstract

Regional CRL(certificate revocation list) in vehicular communications is to partition Full CRL into several small CRLs according to geographic location to keep the size of individual CRLs with smaller. However, since a Regional CRL includes vehicle's revoked certificates within its administrative region, it has to know vehicle' location. For this, how to know vehicle' location effectively corresponding to every region represents a major challenge. This paper proposes a Regional CRL scheme which is envisioned to achieve vehicle's location and to make regional CRLs according to vehicles current location efficiently. The scheme is based on the short-lived pseudonyms defined by WAVE standard. It also acquires issued pseudonyms, vehicle's id and region information whenever a vehicle initiates pseudonyms refill after that, utilizes them to create and distribute the Regional CRL. To keep location privacy-preserving for vehicles, the scheme uses the blockchain technology in the network. The analysis results show that it reduces CRL size and database query time for finding revoked certificates sharply in the vehicle's on-board unit.

차량통신에서 지역별 CRL은 각 CRL의 사이즈를 최소화하기 위해 Full CRL을 다수의 지역별 CRL로 분할한다. 그러나 지역별 CRL은 해당 영역 내에 있는 차량의 취소된 인증서만을 포함해야 하므로 해당 영역에 있는 차량의 위치를 파악해야 한다. 따라서 분할된 영역에 속한 차량의 위치를 효율적으로 파악하는 것이 매우 중요해진다. 본 논문에서는 차량의 위치를 효율적으로 파악하고 차량의 현재 위치를 기준으로 지역별 CRL을 만드는 기법을 제안하였다. 이 기법은 WAVE 표준에 정의된 단기 익명인증서를 활용하며, 차량이 익명인증서를 리필할 때마다 생성된 단기 인증익명인증서, 차량 ID, 지역 정보를 수집하고, 이 정보들을 활용하여 지역별 CRL을 생성하고 배포한다. 그리고 네트워크에서 차량의 위치정보를 보호하기 위해서 블록체인 기술을 사용한다. 분석 결과 제안한 기법은 CRL 사이즈를 줄이고, 차량 위치 프라이버시를 보호하며, 차량의 OBU에서 취소된 인증서를 조회하는 시간을 크게 줄일 수 있다.

Keywords

References

  1. IEEE 1609.2-2016, "IEEE Standard for Wireless Access in Vehicular Environments-Security Services for Applications and Management Messages," IEEE Vehicular Technology Society, Jan. 2016.
  2. H. Seo, etc., "LTE evolution for vehicle-to- everything services," IEEE Communication Magazine, Vol. 54, No. 6, Jun. 2016, pp.22-28. https://doi.org/10.1109/MCOM.2016.7497762
  3. Hwi-Seung Hong, etc., "A Regional Certificate Revocation List Distribution Method based on the Local Vehicle Location Registration for Vehicular Communication," Journal of The Korea Society of Computer and Information, vol. 21, No. 1, pp.91-99, Jan. 2016. https://doi.org/10.9708/jksci.2016.21.1.091
  4. H.G. Kim, "A Certificate Revocation List Distribution Scheme over the eMBMS for Vehicular Networks," Journal of The Korea Society of Computer and Information, vol. 21, No. 10, pp.77-83, Oct. 2016. https://doi.org/10.9708/jksci.2016.21.10.077
  5. LEI Ao, etc., "A Secure Key Management Scheme for Heterogenous Secure Vehicular Communication Systems," ZTE Communications, vol. 14, No. So, pp.21-31, June 2016.
  6. LEI Ao, etc., "A blockchain-based certificate revocation scheme for vehicular communication systems," ELSEVIER Future Generation Computer Systems(online available), April 2019.
  7. Noureddint Lasla, etc., "Efficient Distributed Admission and Revocation using Blockchain for Cooperative ITS," Conference Proc. for New Technologies, Mobility and Security(NTMS), pp.1-5, Feb. 2018.
  8. Ze Wang, etc., "Blockchain-based Certificate Transparency and Revocation Transparency," Financial Cryptography and Data Security, Spring Berlin Heidelberg, pp.144-162 March 2019.
  9. B. Bellur, "Certificate Assignment Strategies for a PKI-based Security Architecture in a Vehicular Network," in Proc. IEEE Globecom 2018, IEEE GLOBECOM 2008, pp.1-6, Nov. 2008.
  10. K. Kim, etc., "SSKM: Scalable and Secure Key Management Scheme for Group Signature Based Authentication and CRL in VANET, " www.mdpi.com/electonics, vol. 8, pp.1-21, 2019.