首页> 外文期刊>Vehicular Communications >Revocation in Vehicular Public Key Infrastructures: Balancing privacy and efficiency
【24h】

Revocation in Vehicular Public Key Infrastructures: Balancing privacy and efficiency

机译:撤销车辆公钥基础设施:平衡隐私和效率

获取原文
获取原文并翻译 | 示例
           

摘要

Modern vehicular security architectures provision authorized vehicles with multiple short-term pseudonym certificates, so users can avoid tracking by rotating among certificates when signing messages. The large number of certificates in the system, however, makes revocation via Certificate Revocation Lists (CRLs) complex and/or inefficient. Two possible solutions for this issue are: (1) frequently provision non-revoked vehicles with few certificates, as done in the Cooperative Intelligent Transport Systems (C-ITS) standard; or (2) provision many encrypted certificates and periodically broadcast "activation codes" for controlling decryption by non-revoked vehicles, as proposed in Activation Codes for Pseudonym Certificates (ACPC), an extension of the Security Credential Management System (SCMS) standard. In this article, we compare such approaches in terms of computational efficiency and privacy preservation. We show that ACPC has advantages over both C-ITS (e.g., support for distributed caching) and CRLs (e.g., avoiding processing overheads on vehicles). We also discuss how ACPC can benefit from the unicast distribution of activation codes, with different trade-offs between privacy and bandwidth savings: getting as much privacy as C-ITS, but downloading 16-byte codes instead of hundreds of kilobytes, or fixing bandwidth costs (resp. privacy level) for a privacy degradation (resp. bandwidth usage) that grows logarithmically with the number of revocations. (C) 2020 Elsevier Inc. All rights reserved.
机译:现代车辆安全架构提供具有多个短期假名证书的授权车辆,因此用户可以避免在签名消息时旋转证书之间的跟踪。然而,系统中的大量证书通过证书撤销列表(CRL)复杂和/或效率低。此问题的两项可能的解决方案是:(1)经常在合作智能运输系统(C-ITS)标准中的少数证书(C-ITS)标准所做的少数证书; (2)提供许多加密证书和周期性广播“激活码”,用于通过非撤销车辆控制解密,如消职码(ACPC)的激活码,安全凭证管理系统(SCM)标准的扩展。在本文中,我们在计算效率和隐私保存方面比较了这些方法。我们表明ACPC具有与C-ITS(例如,支持分布式缓存)和CRL的优势(例如,避免在车辆上的处理开销)。我们还讨论ACPC如何从激活码的单播分发中受益,在隐私和带宽节省之间的不同权衡:获得与C-ITS一样多的隐私,但下载16字节代码而不是数百千字节或固定带宽用于隐私退化(RESP.带宽使用)的费用(RESP。带宽使用情况)以revocation的数量为对数而繁殖。 (c)2020 Elsevier Inc.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号