基于AES-ECDH算法的sdn VANET安全隐私保护系统

IF 1.4 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
IET Networks Pub Date : 2025-07-18 DOI:10.1049/ntw2.70010
Adi El-Dalahmeh, Jie Li, Moawiah El-Dalahmeh
{"title":"基于AES-ECDH算法的sdn VANET安全隐私保护系统","authors":"Adi El-Dalahmeh,&nbsp;Jie Li,&nbsp;Moawiah El-Dalahmeh","doi":"10.1049/ntw2.70010","DOIUrl":null,"url":null,"abstract":"<p>A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.</p>","PeriodicalId":46240,"journal":{"name":"IET Networks","volume":"14 1","pages":""},"PeriodicalIF":1.4000,"publicationDate":"2025-07-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ntw2.70010","citationCount":"0","resultStr":"{\"title\":\"A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm\",\"authors\":\"Adi El-Dalahmeh,&nbsp;Jie Li,&nbsp;Moawiah El-Dalahmeh\",\"doi\":\"10.1049/ntw2.70010\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.</p>\",\"PeriodicalId\":46240,\"journal\":{\"name\":\"IET Networks\",\"volume\":\"14 1\",\"pages\":\"\"},\"PeriodicalIF\":1.4000,\"publicationDate\":\"2025-07-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ntw2.70010\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IET Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ietresearch.onlinelibrary.wiley.com/doi/10.1049/ntw2.70010\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Networks","FirstCategoryId":"1085","ListUrlMain":"https://ietresearch.onlinelibrary.wiley.com/doi/10.1049/ntw2.70010","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

基于软件定义网络(SDN)的车辆自组织网络(VANET)在智能交通系统(ITS)中发挥着至关重要的作用,它通过定期交换与交通、车辆状态和天气状况有关的信息和数据,提高驾驶员和车辆的道路安全。此外,它还为乘客提供娱乐服务。然而,基于sdn的vanet面临着安全挑战,特别是在中央控制单元,使它们容易受到分布式拒绝服务(DDoS)攻击,这可能会破坏整个网络。此外,由于SDN基础设施的可编程性,注入攻击可以操纵流量或产生虚假的危机事件。网络还容易受到各种网络威胁的影响,包括中间人(MITM)、跟踪和重放攻击,因此需要强有力的安全措施。已经提出了几个安全框架来减轻这些风险,但是许多身份验证机制存在较高的计算和通信成本,或者提供针对特定攻击的保护,而对其他攻击无效。为了解决这些限制,我们引入了一个混合安全框架,该框架集成了可信机构(TA)、领导车辆(LV)和其他车辆之间的身份验证系统,以及入侵检测系统(IDS)。认证过程包括TA生成密钥、TA与LV之间以及LV与其他车辆之间的相互认证,同时保证使用AES-ECDH算法进行安全加密。为了进一步提高安全性,本文提出的入侵检测系统利用模糊c均值聚类来检测恶意活动和网络威胁。性能分析表明,我们的方法有效地提高了安全性、隐私性和效率,同时保持了较低的计算开销,性能优于现有的解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Secure Privacy-Preserving System for SDN-Based VANET Using the AES-ECDH Algorithm

A Software-Defined Network (SDN)-based Vehicular Ad Hoc Network (VANET) plays a crucial role in Intelligent Transport Systems (ITS) by enhancing road safety for drivers and vehicles through the periodic exchange of messages and data related to traffic, vehicle status, and weather conditions. Additionally, it offers entertainment services for passengers. However, SDN-based VANETs face security challenges, particularly in the central control unit, making them vulnerable to Distributed Denial-of-Service (DDoS) attacks, which can disrupt the entire network. Moreover, due to the programmability of SDN infrastructure, injection attacks can manipulate traffic or generate false crisis events. The network is also susceptible to various cyber threats, including man-in-the-middle (MITM), tracking, and replay attacks, necessitating robust security measures. Several security frameworks have been proposed to mitigate these risks, but many authentication mechanisms suffer from high computational and communication costs or provide protection against specific attacks while remaining ineffective against others. To address these limitations, we introduce a hybrid security framework integrating an authentication system between the trusted authority (TA), lead vehicle (LV), and other vehicles, along with an intrusion detection system (IDS). The authentication process involves key generation by the TA, mutual authentication between the TA and LV, as well as between the LV and other vehicles, while ensuring secure encryption using the AES-ECDH algorithm. To enhance security further, the proposed IDS utilises Fuzzy C-Means clustering to detect malicious activities and network threats. Performance analysis demonstrates that our approach effectively improves security, privacy, and efficiency while maintaining a low computational overhead, outperforming existing solutions.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
IET Networks
IET Networks COMPUTER SCIENCE, INFORMATION SYSTEMS-
CiteScore
5.00
自引率
0.00%
发文量
41
审稿时长
33 weeks
期刊介绍: IET Networks covers the fundamental developments and advancing methodologies to achieve higher performance, optimized and dependable future networks. IET Networks is particularly interested in new ideas and superior solutions to the known and arising technological development bottlenecks at all levels of networking such as topologies, protocols, routing, relaying and resource-allocation for more efficient and more reliable provision of network services. Topics include, but are not limited to: Network Architecture, Design and Planning, Network Protocol, Software, Analysis, Simulation and Experiment, Network Technologies, Applications and Services, Network Security, Operation and Management.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信