{"title":"基于AES-ECDH算法的sdn VANET安全隐私保护系统","authors":"Adi El-Dalahmeh, Jie Li, Moawiah El-Dalahmeh","doi":"10.1049/ntw2.70010","DOIUrl":null,"url":null,"abstract":"<p>A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.</p>","PeriodicalId":46240,"journal":{"name":"IET Networks","volume":"14 1","pages":""},"PeriodicalIF":1.4000,"publicationDate":"2025-07-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ntw2.70010","citationCount":"0","resultStr":"{\"title\":\"A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm\",\"authors\":\"Adi El-Dalahmeh, Jie Li, Moawiah El-Dalahmeh\",\"doi\":\"10.1049/ntw2.70010\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.</p>\",\"PeriodicalId\":46240,\"journal\":{\"name\":\"IET Networks\",\"volume\":\"14 1\",\"pages\":\"\"},\"PeriodicalIF\":1.4000,\"publicationDate\":\"2025-07-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ntw2.70010\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IET Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ietresearch.onlinelibrary.wiley.com/doi/10.1049/ntw2.70010\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Networks","FirstCategoryId":"1085","ListUrlMain":"https://ietresearch.onlinelibrary.wiley.com/doi/10.1049/ntw2.70010","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm
A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.
IET NetworksCOMPUTER SCIENCE, INFORMATION SYSTEMS-
CiteScore
5.00
自引率
0.00%
发文量
41
审稿时长
33 weeks
期刊介绍:
IET Networks covers the fundamental developments and advancing methodologies to achieve higher performance, optimized and dependable future networks. IET Networks is particularly interested in new ideas and superior solutions to the known and arising technological development bottlenecks at all levels of networking such as topologies, protocols, routing, relaying and resource-allocation for more efficient and more reliable provision of network services. Topics include, but are not limited to: Network Architecture, Design and Planning, Network Protocol, Software, Analysis, Simulation and Experiment, Network Technologies, Applications and Services, Network Security, Operation and Management.