Post-Quantum Tokenized Security for C-V2X
Abstract
Vehicular networks must authenticate high-rate safety messages under tight latency while preserving privacy and remaining secure against post-quantum adversaries. We present$P Q$-Rate, a post-quantum, privacy-preserving, rate-limited credential system for C-V2X. PQ-Rate replaces per-message signatures with a one-round-trip (1-RTT) KEM handshake to derive an AEAD session key, keeping the fast path lightweight. Vehicles obtain unlinkable Rate-Limited Anonymous Tokens (RLATs) from edge issuers (RSU/MEC) via a threshold VOPRF; each token is spent once using a zero-knowledge proof that binds a unique nullifier, enforcing per-epoch budgets without revealing identity. Revocation scales via compact, signed Bloom-filter digests broadcast by RSUs, with optional online disambiguation to handle rare false positives, and accountability is provided by threshold opening of verifiably encrypted token metadata. We prototype PQ-Rate in NS-3 with SUMO-driven mobility and compare against pseudonym-based PKI and verifier-local-revocation group signatures. Metrics include 1-RTT authentication latency, beacon delivery ratio (PDR), channel busy ratio (CBR), verifier throughput, revocation-wire overhead, and realized Sybil capacity. Results show that PQ-Rate maintains sub- 20 ms session setup, improves PDR under high density by reducing airtime overhead, increases verifier throughput via batching and inexpensive decapsulation, and bounds attacker identities to the product of enrolled hardware modules and budget. Revocation digests remain small (on the order of 9-12 KB for thousands of inserts at$10^{-3}-10^{-4}$false-positive targets), supporting frequent broadcast without inflating CBR. PQ-Rate demonstrates that post-quantum security, strong privacy, Sybil resistance, and rapid revocation can be achieved simultaneously within V2X timing constraints.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.