Sudan Jha, Nishant Jha, Deepak Prashar, Sultan Ahmad · 6 authors
Autonomous vehicles offer various advantages to both vehicle owners and automobile companies. However, despite the advantages, there are various risks associated with these vehicles. These vehicles interact with each other by forming a vehicular network, also known as VANET, in a centralized manner. This centralized network is vulnerable to cyber-attacks which can cause data loss, resulting in road accidents. Thus, to prevent the vehicular network from being attacked and to prevent the privacy of the data, key management is used. However, key management alone over a centralized network is not effective in ensuring data integrity in a vehicular network. To resolve this issue, various studies have introduced a blockchain-based approach and enabled key management over a decentralized network. This technique is also found effective in ensuring the privacy of all the stakeholders involved in a vehicular network. Furthermore, a blockchain-based key management system can also help in storing a large amount of data over a distributed network, which can encourage a faster exchange of information between vehicles in a network. However, there are certain limitations of blockchain technology that may affect the efficient working of autonomous vehicles. Most of the existing blockchain-based systems are implemented over Ethereum or Bitcoin. The transaction-processing capability of these blockchains is in the range of 5 to 20 transactions per second, whereas hashgraphs are capable of processing thousands of transactions per second as the data are processed exponentially. Furthermore, a hashgraph prevents the user from altering the order of the transactions being processed, and they do not need high computational powers to operate, which may help in reducing the overall cost of the system. Due to the advantages offered by a hashgraph, an advanced key management framework based on a hashgraph for secure communication between the vehicles is suggested in this paper. The framework is developed using the concept of Leaving of Vehicles based on a Logical Key Hierarchy (LKH) and Batch Rekeying. The system is tested and compared with other closely related systems on the basis of the transaction compilation time and change in traffic rates.
These days, Internet of Things (IoT) is widely used in several real-life applications viz., smart agriculture, smart city, smart healthcare, and smart vehicles. Smart vehicles are interconnected and deliver a variety of sophisticated services to their owners, transit authorities, automobile manufacturers, and other service providers. Smart cars could be exposed to a number of security and privacy risks, including Global Positioning System (GPS) tracking and remote vehicle hijacking. In vehicular IoT, a variety of data are stored in cloud and any alteration in data can cause major road accidents. Blockchain is an evolving technology that can be used for security using decentralization and smart contracts. It is a viable solution for implementing security in vehicular IoTs. In this paper, we presented a blockchain-based methodology to preserve users' privacy while simultaneously boosting vehicle security. The proposed methodology keeps the vehicle data at the servers and related hash values are stored in the blockchain. Thus, the proposed model offers security using decentralization of data. This method outperforms the existing methods in terms of security as well as efficiency.
Through information sharing, vehicles can know the surrounding road condition information timely in Vehicular Adhoc Networks. To ensure the validity of these messages and the security of vehicles, the message authentication, privacy-preserving, and delay problems are three important issues. Although many conditional privacy-preserving authentication schemes have been proposed to ensure secure communication, there still exist some imperfections such as frequent interactions or unlinkability. From this, our paper proposes a novel hierarchical blockchain-assisted authentication scheme to solve these existing issues comprehensively. First, unlinkability is achieved by a dynamic key derivation algorithm. Second, the proposed scheme can reduce correlation processing delay, queuing delay, and deployment costs by adopting hierarchical Vehicle Fog Computing. Third, cross-region authentication is achieved by taking advantage of the properties of blockchain. In addition, we demonstrate our scheme can fulfill the security criteria of the Vehicular Adhoc Network by security analysis. Furthermore, the simulations are carried out to show its availability by using JAVA and NS-3. The findings reveal that the suggested method outperforms earlier schemes in terms of computation cost and communication cost. All in all, making the authentication scheme more efficient and concise is the focus of our future research.
Recent development in intelligent transport systems (ITS) has led to the improvement of driving experience in vehicular ad-hoc network (VANET) systems. Providing a low computational cost with high serving capability, however, is a critical phenomenon in the current VANET system. In the existing scenario, when the authenticated vehicle user moves from one roadside unit (RSU) to another RSU region, re-authentication of the vehicle user is required by the current RSU, which increases the computational complexity. To overcome the above-mentioned challenge, a blockchain-based authentication protocol is developed in this work. In this suggested process, blockchain is integrated with VANET, which enables the authentication of the vehicle user without the involvement of a trusted authority. Moreover, the integrity of the message and privacy of vehicle users are preserved in the blockchain network. Even though many blockchain-based schemes have been proposed recently, the existing schemes were not focused on conditional anonymity. However, in our proposed scheme, conditional privacy is introduced to revoke the malicious vehicles in the case of disputes and to avoid further damage to the VANET system. As a result, the proposed scheme provides an efficient mechanism for anonymous authentication, privacy, and integrity preservation with conditional tracking. Finally, the defense against different security threats is explained in the security analysis section, and the performance investigation section shows the competence and efficacy of our method with similar related methods.
The Internet of Things (IoT) has developed from just an idea or concept to real-time market use-case. Automotive industry is one of the pioneers to adapt to the technology in its budding stage. They are not only focussing on the vehicle's internal features like the traditional self-driven vehicles but have developed a broader-field of view by focussing on communication with other vehicles. The exchange of large volume of data can pose a threat to the user's security. This calls for the need for implementation of multilevel cyber security countermeasures in order to prevent vulnerability to hacking. The use of blockchain has however been one the most useful and advanced technology developed to protect data, i.e., preserve user's personal information/ user's privacy (during communication). This paper mainly deals with the implementation of securing the information regarding next generation intelligent vehicles.
ETC systems today use technology that can be exploited to track toll users. This work develops a GPS-free toll collection that uses a zero-knowledge proof to verify V2X On-board units (OBU) in a way that prioritizes security and privacy while accommodating resource limitations of the embedded technology. Our privacy preserving ETC protocol consists of three parts: a mutual authentication handshake, a zero-knowledge proof challenge, and a verification for toll-payment processing. Bench analysis evaluates embedded systems' limitations of algorithmic operations, and field tests of challenges are conducted in a real-life scenario to show proof-of-concept among V2X interference.
Ahmed Didouh, Houda Labiod, Yassin El Hillali, Atika Rivenq
Despite the decisive contribution of intelligent transport systems in road safety, they also open new vulnerabilities to cyber-attacks, particularly vehicle position-linked attacks. For that reason, centralized systems are becoming increasingly vulnerable to the growth of the connected-vehicle fleets as it becomes more challenging to revoke certificates in real-time. We have proposed a new method that integrates a decentralized, collaborative system to meet these challenges. This method efficiently allows Blockchain integration for vehicular network’s cyber security by dynamically creating communities to revoke malicious vehicles in real-time. This article presents analytical models of the system of real-time revoking certificates and examines our solution’s impact on two important types of attacks in V2X communications, Sybil and the faking position attacks. Our experiments using real V2X hardware demonstrated the feasibility and benefits of real-time revocation via vehicle communities. The results were obtained from consensus implementation in a vehicular network comprising three communicating vehicles and a single roadside unit. In parallel, simulations showed feasibility in large-scale communications. As a result, the exposure and detection times of our solution meet real-time requirements.
As an important extension and modern methodology to fully digitize test management in full vehicle testing, we present the possible advantages of using modern blockchain technology and contrast classical methods. In doing so, we present some of the various requirements for the stakeholders and how these challenges can be met with the help of the new properties of distributed ledgers. This technology has all the properties of a decentralized database and can thus be used as a neutral storage medium, which would ensure the highest level of manipulation resistance and access security. The integration of such a solution requires a fully digitized, modern test environment that can be developed through consistent process digitization. The following four core characteristics of such a system would be:
Cybersecurity in autonomous driving is of utmost importance since a hacked self-driving car could turn into a remote-controlled weapon. Appropriate measures must be taken and implemented to ensure future road safety. The substantially shorter renewal cycles in the hardware (e.g., sensors, computer hardware) and especially software domain compared to the current service life of a vehicle represent a further challenge The use of blockchain technology could enhance security in autonomous driving and thus reduce cybersecurity risks. This paper studies current developments of Swiss pilot projects in autonomous driving and discusses existing solutions for increasing safety of autonomous driving through blockchain.
Modern vehicles have evolved to support connected and self-driving capabilities. The concepts such as connected driving, cooperative driving, and intelligent transportation systems have resulted in an increase in the connectivity of vehicles and subsequently created new information security risks. The original vehicular ad-hoc network term is now emerged to a new term, Internet of Vehicles (IoV), which is a typical application of symmetry of Internet of Things (IoT). Vehicle manufacturers address some critical issues such as software bugs or security issues through remote updates, and this gives rise to concerns regarding the security of updated components. Moreover, aftermarket units such as those imposed by transportation authorities or insurance companies expose vehicles to high risk. Software testing aims to ensure that software products are reliable and behave as expected. Many commercial and open-source software products undergo formal certifications to increase users’ confidence in their accuracy, reliability, and security. There are different techniques for software certification, including test-based certification. Testcase repositories are available to support software testing and certification, such as the Linux Test Project for Linux kernel testing. Previous studies performed various testing and experimental evaluation of different parts of modern vehicles to assess the security risks. Due to the lack of trusted testcase repositories and a common approach for testing, testing efforts are performed individually. In this paper, we propose a blockchain-based approach for a testcase repository to support test-based software and security testing and overcome the lack of trusted testcase repositories. The novel concept Proof-of-Validation to manage global state is proposed to manage updates to the repository. The initial work in this study considers the LTP test suite as a use case for the testcase repository. This research work is expected to contribute to the further development in including evidence generation for testing verification.
Domenico Lattuca, Luca Di Mauro, Francesco Bisconti, Federico Civerchia · 8 authors
Connected and autonomous vehicles run their control algorithms in dedicated on-board computing platforms, which will become obsolete long before the end of the life cycle of the vehicles, severely limiting the evolution of their control software and the deployment of cooperative vehicular applications. A promising solution for this problem is to delegate the most demanding computational tasks to the edge nodes the of Vehicular Ad-hoc Networks, leveraging on the Vehicular Edge Computing paradigm. This requires both low-latency, high-bandwidth communications and secure computing offloading. In this paper, we propose an architecture that ensures supporting secure computation offloading, using the IOTA-VPKI security scheme, without additional delay overhead. Furthermore, to demonstrate the applicability of the proposed scheme to a real case, we measured the time required for the execution of a maneuver plan supervised by an application, the Maneuver Control (MC), located on an edge node. Experimental results show that the described scheme is a very promising solution.
Sonia Alice George, Steffie Maria Stephen, Arunita Jaekel
A vehicular ad hoc network (VANET) consists of vehicles, roadside units, and other infrastructures that communicate with each other with the goal of improving road safety, reducing accidents, and alleviating traffic congestion. For safe and secure operation of critical applications in VANET, it is essential to ensure that only authenticated vehicles can participate in the network. Another important requirement for VANET communication is that the privacy of vehicles and their users must be protected. Privacy can be improved by using pseudonyms instead of actual vehicle identities during communication. However, it is also necessary to ensure that these pseudonyms can be linked to the real vehicle identities if needed, in order to maintain accountability. In this paper, we propose a new blockchain-based decentralized pseudonym management scheme for VANET. This allows the vehicles to maintain conditional anonymity in the network. The blockchain is used to maintain a record of each vehicle and all of its pseudo-IDs. The information in the blockchain can only be accessed by authorized entities and is not available to all vehicles. The proposed distributed framework maintains an immutable record of the vehicle data, which is not vulnerable to a single point of failure. We compared the performance of the proposed approach with a traditional PKI scheme and shown that it significantly reduces the authentication delay.
The vehicular ad-hoc networks (VANETs) are considered a key mechanism for the collection and dissemination of basic safety messages (BSM) in the modern transportation system. However, the presence of compromised or malicious vehicles within the network can disrupt the security of the information and the safety of the passengers. The emergence of a blockchain-based distributed framework in VANETs ensures transparency and security within the network without the assist of a trusted centralized entity. Nonetheless, the presence of the majority of malicious vehicles within the region of interest (ROI) can still bypass the security provided by the state-of-the-art blockchain-based frameworks. In this paper, we propose a Blockchain-assisted Misbehavior Detection and Event Validation (BLAME) framework that can effectively detect the valid traffic events and the malicious vehicles from the ROI by leveraging the neighbor information and the event recorded by the individual vehicles even if they are in majority. The efficacy of BLAME has been validated through simulations in VENTOS simulators and a simulated blockchain environment by extensively addressing different use case scenarios.
As a promising technology, the Internet of Vehicle (IoV) enables vehicles to be connected to the network and sends announcements to roadside units (RSUs) or other vehicles. Nevertheless, because of the open nature of IoV, trust and privacy are confronted with challenges from cyber attacks. Motivated by addressing the above-mentioned problems, a privacy-preserving announcement protocol is constructed in this article, in which an identity-based group signature is used to achieve anonymity of vehicles. In addition, a novel blockchain-based trust management system is designed to guarantee the authenticity of the transmitted messages while realizing the message synchronization. In the meanwhile, a joint proof of work and improved practical Byzantine fault tolerance consensus mechanism is adopted in our scheme to enhance the efficiency of verification. Security analysis as well as simulation results indicate that our proposal is suitable and effective for the IoV environment.
Modern vehicles are no longer simply mechanical devices. Connectivity between the vehicular network and the outside world has widened the security holes that hackers can use to exploit a vehicular network. Controller Area Network (CAN), FlexRay, and automotive Ethernet are popular protocols for in-vehicle networks (IVNs) and will stay in the industry for many more years. However, these protocols were not designed with security in mind. They have several vulnerabilities, such as lack of message authentication, lack of message encryption, and an ID-based arbitration mechanism for contention resolution. Adversaries can use these vulnerabilities to launch sophisticated attacks that may lead to loss of life and damage to property. Thus, the security of the vehicles should be handled carefully. In this paper, we investigate the security vulnerabilities with in-vehicle network protocols such as CAN, automotive Ethernet, and FlexRay. A comprehensive survey on security attacks launched against in-vehicle networks is presented along with countermeasures adopted by various researchers. Various algorithms have been proposed in the past for intrusion detection in IVNs. However, those approaches have several limitations that need special attention from the research community. Blockchain is a good approach to solving the existing security issues in IVNs, and we suggest a way to improve IVN security based on a hybrid blockchain.
Azees Maria, Pandi Vijayakumar, L. Jegatha Deborah, Marimuthu Karuppiah · 5 authors
Smart driving has become conceivable due to the rapid growth of vehicular ad hoc networks. VANETs are considered as the main platform for providing safety road information and instant vehicle communication. Nevertheless, due to the open wireless nature of communication channels, VANET is susceptible to security attacks by malicious users. For this reason, secure anonymous authentication schemes are essential in VANETs. However, when vehicles reach a new roadside unit (RSU) coverage area, the vehicles need to perform reauthentication with the current RSU, which significantly diminishes the efficiency of the entire VANET. Therefore, the introduction of blockchain technology has created opportunities for VANETs to resolve the aforementioned challenges. Due to the decentralized nature of blockchain technology, rapid reauthentication of vehicles is achieved in this paper through secure authentication code transfer between the consecutive RSUs. The security strength of the proposed blockchain-based anonymous authentication scheme against various harmful security attacks is proven in the security analysis section to ensure that it provides better security. In addition, blockchain, as presented in the performance analysis section, is used to substantially diminish the computational cost compared to conventional authentication schemes.
Sumaira Johar, N. Ahmad, Asfandyar Durrani, G. Ali
Intelligent Transportation Systems is the future for safe and secure transportation. Vehicles in the ITS share basic safety information which can prompt the disclosure of the real identity of the vehicles. Thus, adversaries can misuse these safety messages. Pseudonyms are alias granted to vehicles by trusted authorities to conceal their original identities. To avoid linkability, various pseudonym generation and distribution protocols have been proposed. Such protocols pose overheads in the system as they are performed by Central Authorities. Therefore, re-utilizing the existing pseudonyms through shuffling is the most optimal mechanism for ITS. The Blockchain is a digital ledger and tamper-resistant record of transactions. It eliminates the need of central authority as well as provides anonymity of transactions resulting in more secure and privacy protected solution. To handle distribution optimization issue in the pseudonym shuffling process without a central authority, the blockchain is used with its distributed consensus. The shuffling results are logged in blocks as transactions. Pseudonym shuffle randomness is achieved via blockchain and it provides robustness in the structure. When one system fails, the rest would continue to work. The method also provide fully traceable record in case of certification revocation. The existing blockchain-based pseudonym shuffling mechanism uses traditional consensus algorithms to support the cryptography operation. This leads to overhead in terms of execution time and memory usage. This research proposes Proof of Pseudonym consensus protocol for the shuffling scheme to improve the efficiency of consensus as compared to Proof of Work, Proof of Kernel Work and, Proof of Elapsed Time in terms of time and memory. The execution time of Proof of Pseudonym is shorter than other algorithms. The security and privacy analysis revealed that our scheme achieves identity privacy, unlinkability, and non-repudiation properties. Threat analysis evaluates the proposed protocol in terms of both internal and external attacks.
In the near future, intelligent vehicles will be part of the Internet of Things (IoT) and will offer valuable services and opportunities that could revolutionise human life in smart cities. The Vehicular Ad-hoc Network (VANET) is the core structure of intelligent vehicles. It ensures the accuracy and security of communication in vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) modes to enhance road safety and decrease traffic congestion. However, VANET is subject to security vulnerabilities such as denial-of-service (DoS), replay attacks and Sybil attacks that may undermine the security and privacy of the network. Such issues may lead to the transmission of incorrect information from a malicious node to other nodes in the network. In this paper, we present a biometrics blockchain (BBC) framework to secure data sharing among vehicles in VANET and to retain statuary data in a conventional and trusted system. In the proposed framework, we take advantage of biometric information to keep a record of the genuine identity of the message sender, thus preserving privacy. Therefore, the proposed BBC scheme establishes security and trust between vehicles in VANET alongside the capacity to trace identities whenever required. Simulations in OMNeT++, veins and SUMO were carried out to demonstrate the viability of the proposed framework using the urban mobility model. The performance of the framework is evaluated in terms of packet delivery rate, packet loss rate and computational cost. The results show that our novel model is superior to existing approaches.