AI 中文总结
针对现有远程自主代客泊车预约方案身份与通信安全不足的问题,提出SecLAVP协议,经形式化证明、仿真及性能评估,该协议安全且可行。
AI 中文摘要
远程自主代客泊车(LAVP)正被日益采用,以缓解交通拥堵和停车难题。针对大规模停车需求,预约可优化停车管理。然而,现有方案主要聚焦停车请求验证与停车签到,未充分保护乘客上下车过程中的身份合法性与通信安全。为解决该问题,本文提出SecLAVP,一种用于LAVP预约服务的可证明安全三因素认证与密钥协商协议。SecLAVP结合密码、生物特征与智能卡,在上下车点(DP)的协助下,实现乘客与自主车辆(AV)的双向认证并建立用于安全通信的会话密钥。在真实或随机(ROR)模型中,本文形式化证明SecLAVP具备会话密钥安全性;AVISPA仿真显示其可抵御中间人攻击;非正式分析表明其满足15项既定安全目标。最后,对通信开销、计算开销及调度的性能评估表明,SecLAVP可实际部署。
英文摘要
Long-range autonomous valet parking (LAVP) is increasingly adopted to alleviate traffic congestion and parking difficulties. For large-scale parking demand, reservation can improve parking management. However, existing schemes mainly focus on parking request verification and parking check-in, and do not adequately protect identity legitimacy and communication security during passenger drop-off and pick-up. To address this problem, we propose SecLAVP, a provably secure three-factor authentication and key agreement protocol for LAVP reservation services. SecLAVP combines passwords, biometrics, and smart cards. With assistance from the drop-off/pick-up point (DP), the passenger and the autonomous vehicle (AV) achieve mutual authentication and establish a session key for secure communication. In the Real-Or-Random (ROR) model, we formally prove that SecLAVP provides session-key security. AVISPA simulations show that SecLAVP resists man-in-the-middle attacks, while informal analysis demonstrates that it satisfies 15 defined security goals. Finally, performance evaluation in terms of communication overhead, computational overhead, and scheduling shows that SecLAVP is feasible for practical deployment.