Abstract
Vehicular networks require privacy-preserving and secure authentication mechanisms to protect safety-critical communications against evolving cyber threats. Conventional authentication schemes relying on elliptic-curve cryptography (ECC) and RSA are vulnerable to quantum attacks, making them unsuitable for next-generation intelligent transportation systems. This paper proposes a unified post-quantum pseudonymous authentication and key establishment (UPQ-PAKE) scheme for secure vehicular networks. The proposed framework integrates dynamic pseudonymous identity construction, post-quantum digital signatures, and dual ephemeral key encapsulation into a single transcript-bound authenticated key exchange protocol. ML-DSA is employed for mutual authentication, while ML-KEM enables quantum-resistant session key establishment. Dynamic session-specific pseudonyms provide identity privacy and unlinkability. Furthermore, transcript binding, nonce freshness verification, and contributory dual-ephemeral session entropy strengthen the protocol against replay attacks, provide forward secrecy, and resist man-in-the-middle attacks under the quantum polynomial-time adversarial model. Formal security analysis demonstrates that the proposed scheme achieves authenticated key exchange security based on the IND-CCA security of ML-KEM and the EUF-CMA security of ML-DSA. Performance evaluation demonstrates that the proposed authentication technique maintains practical computational and communication overhead and provides post-quantum mutual authentication, dual-directional key establishment, and dynamic unlinkability, making it suitable for large-scale, real-time IoV deployments.
1. Introduction
Rapid advancement in intelligent transportation system (ITS) and Internet of Vehicles (IoV) have transformed vehicular communications into a necessity of modern smart cities. Vehicles are engaged in continuous communication, exchanging safety and beacon messages such as traffic conditions, road hazards, collision warnings, navigation data and emergency notifications through Vehicle-to-Infrastructure (V2I) and Vehicle-to-Vehicle (V2V) communications [1]. In ITS, this communication is crucial to improve traffic management, for efficient transportation, and for the safety of passengers; however, it introduces privacy and cybersecurity challenges. As the wireless communications take place in open networks and channels, adversaries can easily exploit the vulnerabilities to launch various cyber-attacks such as replay attacks, impersonation, man-in-the-middle, message tampering, and session hijacking. This results in catastrophic results for public infrastructure and road safety [2].
Authentication has thus become a basic security requirement in vehicular communication. A secure vehicular authentication approach must ensure integrity, confidentiality, anonymity, authenticity, resistance against cyber-attacks and unlinkability and low latency and lightweight communication overhead for dynamic vehicular environments [3]. Conventional vehicular authentication approaches mainly rely on Public Key Infrastructure (PKI), RSA-based digital signature and Elliptic Curve Cryptography (ECC) for authentication and session/key establishment [4]. Though these approaches provide security under classical assumptions still they are vulnerable to quantum attacks due to quantum computing. Shor’s algorithm can compromise the hard mathematical problems efficiently using conventional cryptographic schemes, such as integer factorization in RSA and the elliptic-curve point multiplication problem underlying ECC [5]. As a result, the traditional vehicular authentication protocols are becoming unsuitable for future quantum enabled communication setups.
To address these challenges, post-quantum cryptography (PQC) has emerged as promising solution for designing cryptographic systems that are resilient to quantum adversaries. Lattice-based cryptographic primitives, especially ML-DSA and ML-KEM standardized by NIST, have recently gained attention due to strong security, computational efficiency and suitability for resource constraints networks [6,7]. Recent studies have also explored the integration of post-quantum cryptography in vehicular communication to obtain quantum-resilient authentication and secure key/session establishment [8]. However, current post-quantum vehicular authentication schemes face severe practical and security limitations.
First, various available authentication approaches fail to ensure strong privacy preservation and unlinkability. Although pseudonyms conceal identities, still insufficiently updated or persistent pseudonyms can help adversaries correlate communications that helps in tracking and behavioral profiling. Hence, dynamic pseudonym generation/update techniques are required for preserving unlinkability in vehicular networks. Second, various post-quantum authentication approaches introduce computational and communication overhead due to size of ciphertext, large signatures and latency issues, that further make them less suitable for real-time vehicular networks. Third, various available approaches are dependent on unilateral ephemeral key exchange techniques providing weak forward secrecy and insufficient contribution entropy from the communicating entities. Furthermore, numerous protocols are not effective to bind all the critical transcript components in authentication process, thereby leaving the network vulnerable to transcript manipulation and man-in-the-middle attacks. Another challenge being faced by vehicular authentication schemes is balancing efficiency and security simultaneously. Strong security generally is achieved at the expense of computational cost, while lightweight approaches compromise privacy significantly [9]. Designing a unified framework ensuring privacy, quantum resilience [10], forward secrecy, transcript integrity, unlinkability, replay resistance and mutual authentication hence remains an open research challenge in the next generation of vehicular communications.
Motivated by these challenges, this paper proposes UPQ-PAKE an authentication and session/key establishment scheme for secure vehicular communication. Figure 1 shows the graphical abstract of the proposed protocol.
Figure 1.
Graphical abstract of the proposed system.
The main contributions of this paper are summarized as follows:
- (i)
- We propose a unified post-quantum pseudonymous authentication and key establishment framework for secure IoV communications.
- (ii)
- We design a dynamic session-specific pseudonym generation mechanism that enhances identity privacy, unlinkability, and resistance to vehicle tracking.
- (iii)
- We develop a dual-ephemeral ML-KEM-based authenticated key establishment protocol that provides contributory entropy and strong forward secrecy.
- (iv)
- We introduce a transcript-bound authentication mechanism that cryptographically binds all session parameters to resist man-in-the-middle and replay attacks.
- (v)
- We present a formal security analysis in the quantum polynomial-time (QPT) adversarial model, demonstrating session key indistinguishability, mutual authentication, identity privacy, and forward secrecy.
The rest of the paper is organized as follows: Section 2 reviews the existing literature, Section 3 presents the system model, adversarial assumptions and design goals, Section 4 elaborates the proposed protocol, Section 5 presents security analysis, Section 6 evaluates the performance of proposed scheme and Section 7 concludes the paper with a future outline.
2. Related Work
2.1. Classical Vehicular Authentication Schemes
Traditional vehicular authentication schemes are heavily dependent on PKI, ECC and bilinear pairing-based authentication for secure V2V and V2I communication. These traditional approaches provide message integrity, efficient authentication, and lightweight computation suitable for vehicular environments. Secure vehicular authentication frameworks have been investigated and emphasized the importance of lightweight and low-latency authentication protocols for real-time vehicular communication [11].
Despite the efficiency of traditional techniques, they rely on computationally hard problems, such as the elliptic-curve point multiplication problem in ECC and integer factorization in RSA. With the arrival of quantum computing, severe threat is posed to these techniques because Shor’s algorithm can solve both problems effectively in polynomial time. Formally, let denote a quantum polynomial-time adversary. Under such an adversarial model, the computational hardness assumptions underlying ECC and RSA can be efficiently broken. Hence,
under enough quantum computations. As a result, ECC- and RSA-based authentications are no longer suitable to be deployed in future ITS.
Furthermore, traditional authentication mechanisms employ static pseudonyms for preserving privacy of users such as
where denotes the registration randomness. However, the repeated use of across multiple communication sessions enables an adversary to correlate different sessions belonging to the same vehicle, thereby compromising unlinkability. Formally,
This allows the long-term behavioral profiling and tracking of vehicles. Therefore, despite being lightweight, classical authentication schemes fail to provide quantum resilience and unlinkability.
2.2. Post-Quantum Vehicular Authentication Schemes
To address the quantum threats, recent studies are focused on integrating post-quantum cryptography (PQC) into vehicular communication systems. Lattice-based cryptography such as ML-KEM and ML-DSA standardized by NIST has emerged as a practical solution due to having strong security and computational efficiency.
A post-quantum secure vehicular authentication protocol has been proposed using lattice-based primitives for secure key establishment and authentication [2]. This scheme demonstrates strong resistance against quantum attacks and improves the robustness of authentication process. However, it reuses static pseudonymous identities during repeated communication enabling the session correlation attacks under passive adversarial observation.
Similarly, PQAKA, a post-quantum authentication and session key agreement approach, has been proposed for the IoV over 5G communication infrastructure [12]. The framework integrates post-quantum key encapsulation and digital signatures for quantum-resistant authentication. Although it has achieved authenticated key establishment successfully, it primarily focuses on the correctness of authentication and does not address transcript integrity and dynamic unlinkability.
Lightweight lattice-based authentication schemes have been investigated mainly for resource-constrained vehicular communication, highlighting the trade-off between communication efficiency and security robustness [11]. The analysis proves that large ciphertext and signature remain one of the major challenges in practical post-quantum vehicular deployments. A quantum-resistant blockchain architecture for VANETs has been proposed, integrating ML-KEM with PoP and PoA consensus for secure message dissemination and identification management [13]. PQ-AuthV is a post-quantum secure authentication scheme for smart vehicular network providing conditional privacy and mutual authentication through aggregated authentication mechanism [2]. QSSNET is a quantum-safe distributed trust architecture for V2X communication combining federated trust with threshold ML-DSA signature and symmetric authentication [14]. V-PISL is a lattice-based post-quantum identity-based signature technique for secure authentication in VANETs leveraging Dilithium for providing resilience against quantum attacks [15].
DAME-IoV is a post-quantum authentication for IoV integrating adaptive security techniques having multi-edge processing for supporting secure and scalable vehicular communication [16]. A quantum-resistant ring signature-based authentication scheme for VANETs using lattice-based cryptography provides privacy-preserving authentication, forward security and message integrity [17]. A secure post-quantum mutual authentication for IoV based on the hardness of the Small Integer Solution (SIS) problem targets secure and efficient communication [18].
Despite having all these advancements, available post-quantum authentication schemes [19,20] suffer from severe limitations. First, some of the protocols are dependent on the resuse of static pseudonyms, which allows adversaries to correlate the authentication sessions. Second, some of the approaches mainly focus on the correctness of authentication while neglecting transcript-bound session derivation. Third, available approaches employ unilateral ephemeral key exchange providing weak forward secrecy.
2.3. Post-Quantum Authenticated Key Exchange Protocols
Authenticated key exchange (AKE) protocols are another important addition to secure post-quantum communication systems. PQ-AKE frameworks use key encapsulation mechanisms (KEMs) for establishing quantum-resistant session keys and integrating digital signatures for mutual authentication simultaneously [21].
AKE protocols have been analyzed under formal security models and established a theoretical foundation for secure session establishment under active adversarial environments [22]. An authenticated post-quantum session protocol integrates ML-KEM for key establishment, AES-256-GCM and ML-DSA for authentication security and protected communication [23]. A lightweight lattice-based authentication and key agreement protocol for multilayer IoT smart grids has been proposed for post-quantum session key establishment and mutual authentication [24]. Lightweight post-quantum key agreement and authentication protocol for smart-home IoT ensures secure session key and mutual authentication against quantum threats [25].
Similarly a three-party password authentication key exchange scheme has been proposed based on the Module Learning with Errors (MLWE) problem for ensuring quantum-resilient authentication and secure key establishment [26]. A Butterfly protocol for mutual authentication and secure key exchange through Remote Quantum Key Distribution (QKD) nodes supports secure communication without a direct QKD link [20]. Blockchain-based batch authentication with a symmetric group key agreement protocol for the MEC environment allows the authentication of multiple users with secure group-wise session key establishment [27]. The RLWE-based three-party AKA scheme for IIoT ensures quantum-resilient mutual authentication and session key establishment [28]. Apart from lattice-based, a QLight-IIOT protocol deploys hash-based security to achieve quantum-resistant authentication that reduces the burden on resource-constrained devices [29]. Blockchain, VAANETs and three-party key agreement known as BCL-3AKA is introduced to target reduced communication and computation overhead [30]. The RLWE-based three-party authentication approach for multi-server networks addresses mutual authentication, session key establishment with applications in various domains including healthcare [31]. A post-quantum AKE framework for BCI/EEG environments combines LWE-based quantum resilience with biometric derived authentication, providing a total new application of PQ-AKE [32].
This analysis demonstrates that transcript integrity and authenticated session derivation are the main requirements for secure communication systems. Modern PQ-AKE protocols employ transcript-bound session derivation functions of the form
where denotes the shared secret, and denotes the transcript-dependent entropy.
Recent authenticated PQ sessions protocols extend this idea further by integrating transcript binding into session derivation process [33]. These protocols compute transcript binders using
Hence ensuring that all the session parameters must be cryptographically bound in final key derivation. This approach strengthens the resilience against transcript manipulation and man-in-the-middle (MITM) attacks.
However, the majority of the available PQ-AKE protocols use unilateral ephemeral entropy contribution such as in Equation (4), where only one communicating party contributes ephemeral randomness. Such approaches provide weak forward secrecy because if a single ephemeral component is compromised, it will affect the overall session entropy. Moreover, the majority of the available PQ-AKE protocols are for generic client–server environments and hence do not address unlinkability and privacy explicitly.
2.4. Research Gaps and Motivation
Despite the latest advances in PQ-vehicular authentication, there are still numerous critical research gaps that need to be addressed as compared in Table 1.
Table 1.
Comparison of recent post-quantum authentication protocols.
First, many of the available PQ vehicular authentication schemes rely on static pseudonymous structures that allow deterministic session correlation attacks. If the same pseudonym is reused across various sessions as mentioned in Equation (3), then an adversary can associate different sessions with the same vehicle trivially. So, existing schemes only provide pseudonymity, but no strong unlinkability is achieved.
Secondly, most of the available PQ-authentication schemes use unilateral ephemeral key exchange and derive session keys using Equation (4), where one party contributes ephemeral entropy only. Such constructions offer limited contribution towards forward secrecy and weak resistance against key compromise attacks.
Thirdly, numerous techniques fail to bind all transcript parameters cryptographically in a single authenticated session derivation. Without complete binding, Equation (5) becomes
This means the protocol is still vulnerable to transcript manipulation and MITM attacks under specific adversarial scenarios.
Fourth, most of the PQ-authentication techniques induce substantial communication overhead due to large signature and ciphertext sizes. This overhead may become problematic in extensive dynamic vehicular setups.
Keeping in view the above-mentioned limitations, this paper proposes UPQ-PAKE, a unified post-quantum pseudonymous authentication and key establishment protocol for secure vehicular communications. It achieves strong privacy, transcript integrity, enhanced forward secrecy, and PQ-resilient authenticated session establishment, and maintains efficiency for real-time vehicular networks.
3. System Model and Design Goals
3.1. Preliminaries on ML-KEM and ML-DSA
ML-KEM: ML-KEM is an NIST-standardized post-quantum key-encapsulation technique defined in FIPS 203 [6]. It consists of three main algorithms: , , and . The algorithm generates an encapsulation key and a corresponding decapsulation key. If the the encapsulation key is given, generates a ciphertext and a shared secret, while uses the corresponding decapsulation key and ciphertext for recovering the shared secret. In the proposed UPQ-PAKE protocol, ML-KEM is used for post-quantum secure session-key establishment between the vehicle and RSU.
ML-DSA: is an NIST-standardized post-quantum digital signature scheme defined in FIPS 204 [7]. It consists of three main algorithms: , , and . The algorithm outputs a signing key and its corresponding verification key, generates a digital signature over a message using signing key, and checks the validity of signature using the corresponding verification key. In the proposed protocol. ML-DSA is used to ensure post-quantum mutual authentication and integrity of the authenticated protocol transcripts.
3.2. System Model
Vehicular networks support both V2I and V2V communication. However, in this work, the proposed protocol is specifically instantiated and evaluated for a V2I communication scenario, where authentication and session-key establishment are performed among a vehicle and an RSU as provided in Figure 2. Direct V2V authentication is outside the scope of this work and is considered a potential extension of the proposed protocol. TA is assumed to be fully trustworthy and secure computationally, responsible for the initialization of the system, generating cryptographic primitives, the registration of vehicles, and the issuance of credentials. Algorithm 1 provides detailed systematic implementation steps of the proposed protocol. During initialization, TA generates global public parameters and PQ-signature keys as
where denotes the TA public verification key, and denotes the corresponding secret signing key. TA maintains secure registration records and updates the authentication policies and validity parameters of certificates periodically.
Figure 2.
System architecture of the proposed UPQ-PAKE protocol involving the Trusted Authority (TA), Roadside Units (RSUs), and Vehicles (Vs). Refer to Table A1 for the detailed mathematical steps.
Each vehicle is equipped with on-board unit (OBU) capable of performing PQ-cryptographic operations. Vehicles communicate dynamically with neighboring vehicles and RSUs while moving within the network. Every vehicle possesses a unique real identity , attributes set , pseudonymous credential and PQ-authentication keys. For preserving the real identity (privacy preserving), the identity of the vehicle is transformed into a hidden commitment as
where denotes randomly generated secret entropy.
RSUs act as semi-trusted entities deployed along the transportation routes for facilitating secure vehicular communications and authentication. Every RSU possesses the computational capability required for executing ML-KEM operations and ML-DSA signature generation and verification. RSU is responsible for authenticating vehicles to establish secure session keys and distributing traffic-related data.
Unlike traditional vehicular systems that rely mainly on long-term identities, the proposed system uses dynamic session-specific pseudonyms. Every vehicle generates a temporary session-specific pseudonym:
where denotes fresh session randomness. This approach prevents deterministic correlation and strengthens the unlinkability across various authentication sessions.
The communication model assumes that all vehicles must communicate in open communication channels susceptible to replay, interception, manipulation and modification by the adversaries. Therefore, all the authentication and session establishment actions must be cryptographically protected through PQ primitives.
The proposed protocol follows a multistage authentication and secure session establishment workflow involving system initialization, credential issuance, mutual authentication and transcript-bound session key derivation. During registration, TA issues authenticated pseudonymous certificates to vehicles. During authentication, RSU and vehicles exchange authenticated transcript-bound messages and establish shared PQ-session secrets using dual ephemeral ML-KEM operation. The final session key is derived as
where and are the two independently established directional ML-KEM shared secrets, binds the authenticated vehicle with the session-key derivation, and denotes the complete canonical transcript binder.
| Algorithm 1 PQ-resilient pseudonymous authentication and key establishment |
| Require: Vehicle identity , vehicle attributes , TA key pair , RSU signing key pair , and security parameter |
| Ensure: Short-lived pseudonym credential and session key Phase 1: Vehicle Registration and Pseudonym Provisioning
|
3.3. Communication Model
Vehicular networks generally support both V2I and V2V communication. In this work, the proposed protocol is specifically the authentication and key establishment protocol and is instantiated and evaluated for the V2I communication scenario between a vehicle and an RSU. Vehicles exchange authenticated safety messages with RSUs and neighboring vehicles periodically through Dedicated Short-Range Communication (DSRC), 5G enabled vehicular communication or future 6G intelligent transportation models.
The communication environment has the following requirements: (i) high node mobility, (ii) short communication sessions, (iii) dynamic topology changes, (iv) frequent authentication requests, and (v) strict latency requirements.
Due to these requirements, the authentication protocols must provide fast establishment of session while ensuring security and privacy. The proposed protocol assumes that vehicles may enter and leave the coverage zone of RSUs dynamically. As a result, the authentication process must support seamless session establishment without requiring repeated long-term credential exposure.
Adversarial Model
The proposed system considers a quantum polynomial-time (QPT) adversarial model where the adversary possesses complete control over public communication channels. The following are the Dolev–Yao adversarial assumptions, so the adversary can: (i) eavesdrop on communication, (ii) replay previous protocol transcripts, (iii) modify transmitted messages, (iv) launch impersonation attacks, (v) inject fabricated authentication messages, (vi) attempt session correlation and tracking, and (vii) perform transcript manipulation attacks.
Formally, the adversary can access the following oracles:
Send Oracle (): Allows passive observation of honest protocol executions.
Reveal Oracle (): Reveals established session keys of non-test sessions.
Corrupt Oracle (): Reveals the long-term secret keys of compromised entities.
Test Oracle (OTest): The adversary may issue this query once to a fresh completed session. The challenger then selects a random bit b. So if b = 1, the oracle returns the original established session key; otherwise, it returns a uniformly random string of same length. The adversary generates a guess , and its AKE advantage can be defined according to its capability to distinguish the real key from a random value. A session is considered fresh only if its session key has not been revealed and the corresponding relevant ephemeral secrets have not been exposed before completion of the tested session.
The adversary is assumed to be capable of performing quantum attacks against traditional PKI assumptions. Therefore, ECC and RSA-based schemes are considered insecure under the proposed threat model. However, the adversary cannot break the following efficiently: (i) IND-CCA security of ML-KEM, (ii) EUF-CMA security of ML-DSA, (iii) pseudorandomness of HKDF, and (iv) collision resistance of hash functions.
3.4. Pseudonym Lifecycle and Conditional Traceability
During registration, TA verifies real identity and maintains a protected registration mapping:
For every authentication session, the vehicle derives a session-specific pseudonym using fresh randomness as mentioned in Equation (9). Credential revocation is performed against the base credentials issued by the TA and associated public key instead of every transient session pseudonym. The TA distributes the authenticated revocation status to RSU. When administratively or legally authorized accountability is required, the TA can then resolve the authenticated base credentials to its protected registration record. Hence, conditional traceability is available to the TA, while peer vehicles and external observers cannot directly resolve the real identities of vehicles from its session-specific pseudonym.
3.5. Architectural and Deployment Assumptions
The following architectural and deployment assumptions are made for the proposed protocol. First, RSU and vehicles obtain authenticated time from a trusted synchronization source or RSU-assisted time synchronization. The received timestamp t is only considered fresh if
where represents deployment-specific clock-skew tolerance. Nonce validation is used, as it does not rely on timestamp synchronization. Second, the TA is the major trusted body that distributes or anchors its public verification keys securely during system provisioning. RSU and vehicle public authentication keys are bound to the TA-assisted credentials, ensuring communicating entities verify their authenticity before accepting messages. Third, credential revocation is managed by the TA through authenticated revocation approach. THe TA distributes signed certificates revocation list (CRLs) periodically or similar authenticated credential-status information periodically to RSU. RSU then checks the revocation status and validity of the presented pseudonym credential before completing authentication. Fourth, the TA maintains protected mapping between registered real identities and corresponding base credentials and pseudonym record. This mapping never gets exposed during V2I and V2V authentication and can only be accessed for authorized credential management, identity-resolution and revocation. Finally, communication among the TA and RSU is assumed to occur over an integrity-protected and authenticated control channel. This channel is used for the credential provisioning, policy updates, trust-anchor distribution and dissemination of the revocation status. Compromise of the TA is outside of the scope of the threat model, as the TA constitutes the root of trust for the proposed system.
In addition to a QPT adversary, the security model also considers concurrent protocol sessions, attempts to exploit compromised network entities, and compromise of the RSU or vehicle long-term credentials. An adversary may observe, replay, modify, or inject messages across multiple sessions and may also try to compromise individual RSUs or vehicles. The compromise of session-specific ephemeral secrets is separately treated in forward secrecy.
3.6. Design Goals
The proposed protocol is designed to satisfy the following functional and security objectives:
- (i)
- Quantum Resilience: The proposed protocol remains secure against quantum polynomial-time adversaries by incorporating the NIST-standardized post-quantum cryptographic primitives ML-KEM and ML-DSA.
- (ii)
- Mutual Authentication: The proposed protocol must ensure bidirectional authentication among RSUs and vehicles through authenticated transcript verification:
- (iii)
- Dynamic Unlinkability: The proposed protocol must prevent session correlation attacks through dynamic pseudonym generation using Equation (9), ensuring
- (iv)
- Forward Secrecy: The proposed protocol must protect previous session keys even if the long-term authentication keys are compromised. Therefore, session key derivation uses dual ephemeral entropy using Equation (10).
- (v)
- Replay Resilience: The proposed protocol incorporates nonce and timestamp freshness validation:to prevent the replay authentication messages.
- (vi)
- Transcript Integrity: All authentication and key exchange parameters are bound cryptographically throughthereby preventing transcript manipulation MITM attacks.
- (vii)
- Lightweight Communication: The proposed protocol must ensure low computational and communication overhead as required for highly dynamic vehicle communication networks with strict latency constraints.
4. Proposed UPQ-PAKE Protocol
The following equations define the UPQ-PAKE protocol operations formally using the notation and cryptographic primitives introduced previously.
4.1. Protocol Overview
The proposed protocol provides secure communication for IoV networks employing dynamic pseudonymous identity generation, transcript-bound mutual authentication and dual-ephemeral key establishment in a unified authentication framework. Unlike traditional authentication protocols, the proposed protocol uses ML-KEM and ML-DSA for session key establishment and PQ-mutual authentication. It consists of four major phases:
- (i)
- System Initialization Phase;
- (ii)
- Vehicle Registration Phase;
- (iii)
- Mutual Authentication Phase;
- (iv)
- Session Key Establishment Phase.
The major notations and symbols used in the proposed protocol are mentioned in Table 2.
Table 2.
Notation summary.
4.2. System Initialization Phase
During initialization, TA generates a global public/private key pair and initializes the PQ-cryptographic environment. TA generates the ML-DSA signing key pair using Equation (7). It also defines the security parameter , the secure hash function , the key derivation function , and the certificate validation policies. The resulting public system parameters are published as
The corresponding private signing key, , is securely protected within TA.
4.3. Vehicle Registration Phase
Before participating in communication, every vehicle must get registered with TA.
The vehicle first selects the random registration entropy:
The vehicle identity commitment is generated using Equation (8). The vehicle then generates its long-term PQ-signature keys such as
For preserving anonymity, the vehicle constructs a pseudonymous identity as
where denotes fresh pseudonym randomness. The TA maintains the following protected registration record for accountability and revocation:
The registration record is then constructed as
TA signs the RegRec using ML-DSA as
The authenticated pseudonymous certificate becomes
Finally, the vehicle stores
To avoid exposing persistent base pseudonym during authentication, TA pre-issues a pool of short-lived pseudonym credentials for every registered vehicle. Every credential binds a session pseudonym to the authenticated verification key of vehicle without disclosing the base pseudonym and real identity .
4.4. Mutual Authentication Phase
When a vehicle enters the communication range of an RSU, the authentication phase starts.
The vehicle verifies the integrity of its certificate first:
The vehicle generates its ephemeral ML-KEM key pair:
Similarly, RSU generates its own ephemeral KEM key pair:
The ephemeral ML-KEM key pair in Equations (30) and (31) get generated independently for every authentication session through a cryptographically secure pseudorandom number generator (CSPRNG). These ephemeral keys are not reused across various authentication session.
To strengthen unlinkability, the vehicle transforms its pseudonym using fresh session entropy dynamically using
The dynamic session pseudonym gets computed using Equation (9). This construction ensures that pseudonyms are different across sessions as
Thus, deterministic session correlation is preserved.
The vehicle then generates authentication freshness parameters:
The authentication request becomes
The vehicle then computes the authentication signature:
The vehicle transmits the message: to the RSU.
4.5. RSU Verification and Session Establishment
When the authentication request is received by RSU, it validates: (i) TA signature contained in , (ii) checks credential validity/revocation, (iii) in matches the one authenticated by , and (iv) obtains from valid pseudonym credential and verifies .
The RSU verifies the TA signature first:
It then verifies the vehicle’s authentication signature:
Freshness validation is performed using Equation (16). The RSU then establishes the dual ephemeral session secrets. The first shared secret is
The RSU generates fresh nonce and timestamps:
4.6. Transcript Binding Phase
To resist transcript manipulation and MITM attacks, all the critical session parameters are bound to transcript binder cryptographically using Equation (17).
RSU signs the transcript binder:
The RSU transmits the message to the vehicle.
4.7. Session Key Derivation Phase
The vehicle verifies the signature of RSU first:
Once the RSU response is verified, the vehicle decapsulates the RSU generated ciphertext through its own ephemeral secret key:
The vehicle also then decapsulates the second shared secret using the ephemeral public key of RSU
The vehicle then sends back to RSU, authenticated by the final transcript signature
RSU verifies the signature and performs:
The final authenticated session key is derived:
The session depends on dual ephemeral entropy, transcript integrity and authenticated session context.
After successful derivation and confirmation of the session keys in Equation (50), the ephemeral secret keys and the intermediate shared secrets are erased securely once they are no longer required. This limits the exposure of completed sessions in the event of subsequent long-term key compromise.
4.8. Correctness Analysis
Correctness needs both the communicating entities to derive the identical shared secrets and same session key. By ML-KEM correctness,
RSU encapsulates with and the vehicle decapsulates the corresponding ciphertext using . Similarly,
Since the vehicle encapsulates with and RSU decapsulates using . Therefore,
Thereby, authenticated session agreement is ensured.
5. Security Analysis
5.1. Security Assumptions
Definition 1
(IND-CCA Security of ML-KEM). Let be a quantum polynomial-time (QPT) adversary interacting with an ML-KEM challenger. The ML-KEM primitive is said to be IND-CCA secure if
where is the random challenge bit selected by the challenger, is the adversary’s guess, and denotes a negligible function in the security parameter λ.
Definition 2
(EUF-CMA Security of ML-DSA). The ML-DSA signature scheme is existentially unforgeable under adaptive chosen-message attacks if
for every quantum polynomial-time (QPT) adversary , where denotes a negligible function in the security parameter λ.
Definition 3
(Random Oracle Assumption). The hash function:
is modeled as a random oracle.
5.2. Formal Security Definitions
Definition 4
(Authenticated Key Exchange Security). The proposed protocol satisfies AKE security if no adversary can distinguish a real session key from a uniformly random key of the same length through a Test oracle with non-negligible advantage. Let be the challenge bit selected by the Test oracle and be the adversary’s guess. The AKE advantage is defined as
Partnering: Two completed protocol sessions are considered partnered if they get executed by the intended vehicle and RSU peers, also have matching session identifiers derived from the authenticated protocol transcript, and accept the same session key.
Definition 5
(Forward Secrecy). The protocol achieves forward secrecy if the long-term secret keys compromise does not reveal the previously established session keys.
Definition 6
(Dynamic Unlinkability). The proposed protocol achieves unlinkability if an adversary does not determine whether two sessions belong to the same vehicle.
Let λ be the security parameter, and the proposed protocol uses three cryptographic primitives: a collision-resistant hash function , post-quantum signature scheme ML-DSA and a post-quantum key encapsulation ML-KEM. Security of the proposed protocol is analyzed with the assumption that ML-DSA is unforgeable under the chosen message attack and ML-KEM is indistinguishable under the chosen ciphertext attacks, while HKDF behaves as a pseudorandom key derivation function.
The client generates a random value such as
and computes hidden identity commitment as mentioned in Equation (8), where real identities and are hidden using secret randomness . So an adversary who finds cannot recover unless it can invert the hash function or guess . The possibility of this recovery is bound by
is negligible.
The client then generates a post-quantum signature key pair using Equation (20). The pseudonymous identity is computed using Equation (21), where , and it is ensured that the pseudonym is bound to hidden commitment and the public key , while random value r prevents deterministic pseudonym generation. Hence, even if the same vehicle gets registered again, a new r will result in different . Registration record is defined in Equation (23) and the TA signs this record using Equation (24). The certificate is issued through Equation (25). The verifier will accept this certificate only if Equation (29) holds.
Therefore, an adversary cannot create a valid certificate unless it forges the TA signature. So formally,
During authentication, clients generate an ephemeral KEM key pair using Equation (30) and generates a fresh nonce as and timestamp as . So the authentication message is generated using Equation (36). The client signs the authentication transcript using Equation (37). The verifier validates the client using Equation (39). If an adversary impersonates the client successfully without knowing , then the adversary is successful in forging a valid ML-DSA signature. Hence,
The verifier also checks the freshness by validating Equation (16) and ensuring that
where is the replay cache. Equations (16) and (62) prevent replay attacks. A replayed message will have an expired timestamp or previously used nonce. Therefore,
If nonce storage is implemented correctly, then the first term becomes negligible. After successful validation, the verifier encapsulates a shared secret using Equation (40). The verifier generates its own timestamp and nonce and timestamp as . The transcript binder gets computed using Equation (17). If an adversary modifies any value in Equation (17), the transcript binder gets changed. Therefore, the tampering of transcript is detected when the verifier signs using Equation (43). The client verifies the response of the verifier using Equation (14), which provides the verifier’s authentication. So, if an adversary tries to impersonate any verifier, it must forge . Thus,
The client will decapsulate the cipher using Equation (45). By KEM correctness,
where denotes a negligible function in the security parameter λ.
The final session key is derived using Equation (50). It shows that the session key is dependent on both the authentication transcript β and post-quantum shared secret . So even if an adversary can observe all the public messages, it still cannot compute without recovering .
5.3. Authenticated Key Exchange Security
Game . represents the real execution of the proposed protocol:
Game . Replace the random oracle outputs with uniform random values:
where represents the number of hash queries.
Game . Replace ML-KEM shared secrets with uniform random strings, then
Game . Replace HDKF output with a random session key:
Combining all games,
5.4. Mutual Authentication Theorem
The proposed protocol provides mutual authentication among the verifier and the vehicle. For vehicular authentication, the verifier accepts using Equation (39). Therefore, if an adversary tries to impersonate a vehicle, it must produce a valid signature without knowing . Hence,
For authentication of the verifier, the client accepts. Hence,
The total probability of authentication failure is bound by
5.5. Dynamic Unlinkability Analysis Theorem
The proposed protocol achieves dynamic unlinkability under the random oracle model.
During every authentication session j, the vehicle generates a fresh session-specific pseudonym as mentioned in Equation (9), where is uniformly selected session entropy. Assume an adversary attempts to determine whether two observed sessions belong to the same vehicle. The adversary observes Equation (15), which means the adversary cannot correlate authentication sessions with non-negligible probability. Hence, the protocol achieves dynamic unlinkability and prevents the long-term tracking of vehicles.
5.6. Replay Attack Resistance Theorem
The proposed protocol resists replay attacks under the uniqueness of nonce and freshness of timestamp. The verifier accepts a vehicle message using Equations (16) and (62). So a replayed message needs to satisfy both the uniqueness of the nonce and the freshness of the timestamp. Since is selected randomly from , the probability of guessing the fresh nonce is
where q is the total number of protocol sessions. Thus,
For a previously accepted transcript, the nonce is contained in , so the replay is rejected even if the timestamp lies within the freshness window. The EUF-CMA security of ML-DSA is relevant only if an adversary modifies the replayed transcript and tries to attempt to generate a valid signature for the modified message.
5.7. Man-in-the-Middle Attack Resistance Theorem
The proposed protocol is resilient to man-in-the-middle attacks because authentication and key-establishment parameters are bound to a single canonical transcript binder cryptographically. Specifically, contains a session-specific pseudonym, both ephemeral public keys, both directional ML-KEM ciphertexts, nonces, and timestamps. Hence, any modification to these values generates a different transcript binder. So if an adversary tries to modify any value, then the altered binder becomes
For an attack to remain undetected, the adversary must satisfy
This implies a collision hash unless the transcript is unchanged. Therefore,
Moreover, the attacker must also forge the signature of the verifier. Hence,
5.8. Forward Secrecy Analysis Theorem
Assuming that ML-KEM is IND-CCA secure and HKDF is the pseudorandom key derivative function, the proposed protocol provides forward secrecy. For any quantum polynomial-time adversary , the forward secrecy advantage is bound to
where is an efficient reduction algorithm and is negligible.
5.9. Session Key Indistinguishability Theorem
The proposed protocol achieves the indistinguishability of the session key only if ML-KEM is IND-CCA secure, ML-DSA is EUF-CMA secure, HKDF is pseudorandom and H is collision resistant.
For any quantum polynomial-time (QPT) adversary ,
The protocol follows a hybrid argument, where in real game , the adversary sees the real protocol execution. In game , the game gets aborted if an adversary forges either the verifier’s signature or the client’s signature . The difference between both games is bound by
In game , the real KEM shared secret ss gets replaced by uniform random value u. So, any adversary detecting this replacement can be used to break the IND-CCA security of ML-KEM as Equation (68).
To improve reproducibility, all performance experiments were executed using the hardware and software configuration reported in Table 3. The simulation duration, cryptographic parameter sets, number of vehicles, mobility range, number of RSUs, and communication settings were kept identical across repeated experiments. The same parameter configuration was used for all schemes included in the comparative evaluation.
Table 3.
Experimental setup and simulation parameters.
Each experimental configuration was executed independently 20 times. For each reported performance metric, the arithmetic mean and standard deviation were computed across 20 independent runs. Accordingly, the results are reported as mean ± standard deviation to characterize run-to-run variability.
In game , the session key
In the corresponding hybrid games, the two directional ML-KEM shared secrets and are replaced by the independent uniformly random values and , respectively.
In , the adversary receives a random key independent of its view. Hence, combining hybrid gaps as
5.10. Computational Complexity
Assume adversary runs t, hash queries qH, and session queries qs, then
5.11. Identity Privacy
Scope of Unlinkability and Metadata Privacy
The dynamic pseudonym approach of UPQ-PAKE ensures cryptographic unlinkability by restricting external observers from correlating authentication sessions directly through persistent pseudonymous identifier. However, this property does not ensure complete protection against physical-layer or cross-layer vehicle tracking. An adversary may try to attempt correlating different sessions through auxiliary metadata such as mobility trajectory, vehicle location, speed, network-layer identifier, message timings or radio-frequency fingerprints. This information is external to the cryptographic transcript presented in the security model. Hence, the unlinkability claim of UPQ-PAKE is limited to cryptographic identifiers and authentication transcripts and does not claim resistance against physical-layer or metadata-based tracking attacks. Addressing these cross-layer correlation attacks need a complementary privacy approach and is considered out of the scope of the present work.
During authentication, neither real identity nor persistent base pseudonym gets transmitted over an open channel. Rather, the vehicle uses a session-specific pseudonym and TA-authorized short-lived pseudonym credential . As a result, external observers cannot correlate the authentication session directly through persistent identifier provided in the authentication credential. The mapping between pseudonym credential and registered vehicle is maintained by the TA only for the authorized accountability and revocation. So, an adversary trying to recover from must invert both hashes or guess the hidden randomness of and . Therefore,
Thus, the proposed protocol provides pseudonymous identity privacy.
5.12. DoS and Availability Considerations
For improving resilience against Denial-of-service (DoS) and resource exhaustion attacks, RSU performs inexpensive checks such as timestamp, message-format, credential-status and nonce validation before executing expensive ML-DSA verification and ML-KEM operations. Practical deployment may require rate limiting and bounded request queues for restricting excessive authentication requests. All these techniques mitigate computational flooding; however, complete DoS prevention is out of scope of the proposed protocol.
6. Performance Evaluation
6.1. Experimental Setup and Implementation Environment
For evaluating the practical feasibility of the proposed protocol, it has been implemented using standardized PQ cryptographic primitives based on NIST-PQ standardization framework. The implementation uses ML-KEM (former CRYSTALS-Kyber) for PQ key encapsulation and ML-DSA (former CRYSTALS-Dilithium) for PQ-digital signatures. The implementation environment is given in Table 3. All experiments were conducted on a workstation equipped with an Intel® CoreTM i7-12700 12th-generation processor, operating at a base clock frequency of 2.10 GHz and a maximum turbo frequency of 4.90 GHz. The system was equipped with 16 GB DDR4 RAM. No GPU acceleration was used for reported cryptographic and simulation measurements.
The evaluated schemes are compared under consistent security assumptions, message count considerations, cryptographic parameter levels, and protocol design, and communication conditions are considered while interpreting the reported communication and computational overhead for a fair comparison. Hence, the comparison is intended to only provide a relatable assessment instead of an absolute performance ranking across heterogeneous deployment settings. The cryptographic operation costs and sizes of parameters used in the evaluation are based on the adopted ML-KEM and ML-DSA parameter settings and the benchmark environment described in this section.
6.2. Computational Overhead Analysis
The computational cost of the proposed protocol is analyzed based on the execution cost of individual PQ cryptographic operations. Table 4 represents the symbols used for the operations. The computation overhead is divided into (a) vehicle-side overhead, and (b) RSU-side overhead.
Table 4.
Computational cost notation.
(a) Vehicle-Side Computational Overhead
During authentication and session establishment, the vehicle performs: (i) two ML-DSA signature generation, (ii) one ML-DSA signature verification, (iii) one ML-KEM key generation, (iv) one ML-KEM encapsulation, (v) one ML-KEM decapsulation, (vi) multiple hash function evaluations, and (vii) one HKDF derivation.
The total computational overhead at vehicle-side is
(b) RSU-Side Computational Overhead
RSU performs: (i) two ML-DSA signature verification operations, (ii) one ML-DSA signature generation, (iii) one ML-KEM signature generation, (iv) one ML-KEM encapsulation operation, (v) one ML-KEM decapsulation, (vi) transcript generation, (vii) multiple hash function evaluations and (viii) one HKDF derivation.
The computational overhead at RSU-side is
Table 5 shows the computational cost comparison.
Table 5.
Comparison of computational overhead.
The proposed scheme however introduces additional computational cost as compared with conventional ECC-based authentication due to PQ cryptographic operations. However, the measured authentication latency stays within the evaluated operational range. The additional cost is a security–performance trade-off that is raised due to quantum-resilient mutual authentication, dual key establishment and transcript binding.
Although the proposed protocol introduces a slightly higher transcript processing cost, it achieves stronger forward secrecy, dynamic unlinkability and transcript integrity compared with the available scheme. Figure 3 shows the computational overhead comparison. As mentioned in Table 6, both the vehicle and RSU perform one ML-KEM encapsulation and one ML-KEM decapsulation during session establishment. RSU performs verification of the vehicle’s authentication and also final transcript signatures while TA handles the registration and offline operations.
Figure 3.
Comparison of computational overhead between the proposed UPQ-PAKE scheme and existing authentication schemes under the adopted benchmark settings.
Table 6.
Practical computational requirements of UPQ-PAKE entities.
6.3. Communication Overhead Analysis
Communication cost shows important performance metrics due to latency and bandwidth constraints. For the byte-level communication analysis, every nonce and is represented as a 256-bit random value (32 bytes), consistent with SHA3-256 security parameter. Timestamps and , and the credential validity field , are encoded as 64-bit unsigned integer values (8 bytes each). These fixed-width encodings are used consistently in the communication-overhead calculation.
The proposed protocol transmits the following:
- (i)
- Vehicle certificate ();
- (ii)
- Authentication message ();
- (iii)
- ML-DSA signatures;
- (iv)
- ML-KEM ciphertexts;
- (v)
- Nonces and timestamps.
The total communication cost is computed as
Using the ML-KEM-768 and ML-DSA-65 parameter sizes as presented in Table 7.
Table 7.
Byte-level communication overhead of the UPQ-PAKE authentication exchange.
The total communication cost is approximately
The resulting communication overhead of 19,884 bytes (≈19.88 kB) shows an aggregate protocol-level cryptographic payload of the complete UPQ-PAKE authentication exchange instead of a single-frame transmission. Depending on the underlying C-V2X, DSRC, or 5G NR-V2X transport and the effective MTU, the authentication exchange may require fragmentation across multiple lower-layer transmissions. As a result, practical latency may include serialization, retransmission, transmission, contention and fragmentation costs in addition to the cryptographic computation.
That remains practical for modern vehicular communication frameworks. Figure 4 represents communication overhead comparison.
Figure 4.
Comparison of communication overhead between the proposed UPQ-PAKE scheme and existing authentication schemes under the adopted benchmark settings.
6.4. Authentication Delay Analysis
Authentication delay is another critical factor in highly dense communication environments where rapid authentication is required.
Total authentication delay is
where represents computational delay and shows transmission delay.
Computational Delay:
Due to lightweight transcript construction and efficient lattice-based operations, the proposed protocol maintains practical authentication latency highly suitable for the real-time vehicular communications. Figure 5 represents the authentication delay comparison.
Figure 5.
Comparison of authentication delay between the proposed UPQ-PAKE scheme and existing authentication schemes under the adopted benchmark settings.
A comparatively higher authentication delay of the proposed protocol is an expected security–performance trade-off resulting from the use of ML-DSA signatures, bidirectional ML-KEM operations, freshness verification and transcript binding. Therefore, the objective of the proposed protocol is not to minimize authentication latency relative to the traditional schemes but to maintain the delay within operationally acceptable range while providing post-quantum security, dynamic unlinkability and forward secrecy. For deployment-oriented interpretation, the authentication delay should be evaluated against the explicitly defined application-level latency requirement, and the 19.88 kB authentication payload should be assessed against the effective bandwidth available for underlying V2X link. Accordingly, the reported results show the protocol-level feasibility under the adopted benchmark settings instead of a claim of minimum authentication delay.
6.5. Scalability Analysis
Vehicular networks observe continuously changing node density and authentication requests. Hence, the scalability is essential. Let be the active vehicles and be the RSUs. So, the authentication complexity grows linearly:
Because every authentication session is established independently, no blockchain consensus is required and no heavy pairing operations are involved. Hence, the proposed protocol stays scalable under heavy vehicular densities. Figure 6 shows the scalability analysis.
Figure 6.
Authentication delay versus the number of vehicles under the adopted benchmark settings.
The replay and MITM resistance of the proposed protocol is evaluated analytically. For replay attacks, an adversary succeeds only if the freshness techniques are bypassed, with nonce-collision probability bounded by the security parameter and number of protocol sessions. For MITM attacks, successful transcript manipulation needs either producing a collision in the transcript-binding hash or forging a valid ML-DSA signature. As a result, the MITM success probability is limited to the collision-resistance advantage of the hash function and the EUF-CMA advantage against ML-DSA.
The present evaluation is intended for protocol and cryptographic-level feasibility instead of providing a complete field deployment benchmark. It does not completely reproduce vehicular wireless effects including fading, high-speed mobility, interference, handovers, packet loss, congestion, or hardware-specific OBU constraints. Hence, the reported results must be interpreted within the stated simulation and benchmark assumptions. Since the authentication session of every vehicle is processed independently, the overall authentication workload increases linearly with the number of concurrent vehicle requests approximately. Therefore, scalability in dense vehicular environments depends on the processing capacity of the serving RSU and the total number of simultaneous authentication requests. Additional RSUs can however distribute the authentication workload across different coverage regions, supporting larger vehicular populations without changing the core protocol.
7. Conclusions
This paper presents UPQ-PAKE: a unified post-quantum-resilient anonymous authentication and key establishment protocol for ITS. The proposed scheme is designed to address the growing privacy and security concerns in next-generation vehicular communications under both conventional and quantum adversarial models. Unlike traditional authentication schemes that remain vulnerable to quantum-enabled cryptoanalysis, the proposed scheme integrates ML-DSA- and ML-KEM-based PQ primitives for providing secure mutual authentication, transcript-bound session establishment, dynamic pseudonym generation and forward secrecy. It eliminates various critical weaknesses being observed in conventional vehicular authentication schemes such as static binding, insufficient forward secrecy, weak/no transcript binding and vulnerability to MITM and replay attacks. By integrating dual ephemeral ML-KEM encapsulation, nonce-based freshness validation, dynamic session-bound pseudonyms, and transcript integrity verification using parameter , the proposed protocol strengthens the authentication robustness significantly while preserving unlinkability and user privacy. The formal security analysis shows that the proposed protocol achieves authenticated key-exchange security, mutual authentication, resistance against MITM and replay attacks, and dynamic unlinkability under quantum polynomial-time adversarial model. The simulation-based performance evaluation confirms that the proposed scheme maintains practical computational overhead, authentication latency, communication efficiency suitable for highly dynamic vehicular communication setups. Although the use of PQ-cryptographic primitives introduces slightly larger ciphertexts and signature sizes compared with the conventional ECC-based schemes, the protocol achieves stronger long-term security guarantees substantially while maintaining scalability under increasing vehicular density and communication sessions.
Author Contributions
Conceptualization, R.K., S.U.J. and A.S.; Methodology, R.K., S.U.J. and S.A.F.A.-H.; Software, R.K., S.U.J., S.A.F.A.-H. and A.S.; Validation, R.K., S.U.J. and S.A.F.A.-H.; Formal analysis, N.J. and S.A.F.A.-H.; Investigation, R.K., S.U.J., M.A.R., L.F.S., N.J., S.A.F.A.-H. and A.S.; Resources, M.A.R., L.F.S. and N.J.; Data curation, N.J. and S.A.F.A.-H.; Writing—original draft, R.K., S.U.J. and L.F.S.; Writing—review & editing, R.K., S.U.J., L.F.S. and A.S.; Visualization, S.U.J., N.J. and A.S.; Supervision, M.A.R. and L.F.S.; Project administration, S.U.J., M.A.R. and A.S. All authors have read and agreed to the published version of the manuscript.
Funding
This scientific paper is derived from a research grant funded by Taibah University, Madinah, Kingdom of Saudi Arabia—with grant number (448-16-1216).
Data Availability Statement
The original contributions presented in this study are included in the article. The authors deposited a single public reproducibility package: (https://github.com/usmanjamilsyed/Autonomous-Quantum-Resistant-Vehicular-Network-Mechanism, accessed on 10 September 2026) containing this work source code, simulation and its results at Github data repository for the readers of this journal and to benefit wider research community. Further inquiries can be directed to the corresponding author.
Acknowledgments
Courtesy and thanks: We thank all collaborators and institutions contributing in this research work. We also acknowledge Github for providing collaborative environment.
Conflicts of Interest
The authors declare no conflicts of interest.
Appendix A
Table A1.
Protocol message exchange and key derivation steps.
References
- Dutta, A.; Samaniego Campoverde, L.M.; Tropea, M.; De Rango, F. A Comprehensive Review of Recent Developments in VANET for Traffic, Safety & Remote Monitoring Applications. J. Netw. Syst. Manag. 2024, 32, 73. [Google Scholar] [CrossRef] [Scilit]
- Rajasekaran, A.S.; Das, A.K.; Maria, A.; Ahmed, G.F.; Merlec, M.M.; In, H.P.; Pal, S. PQ-AuthV: Post-Quantum Secure Authentication with Aggregated Signatures in IoT-Enabled Smart Vehicle Networks. IEEE Internet Things J. 2026, 13, 31809–31822. [Google Scholar] [CrossRef] [Scilit]
- Yang, Q.; Zhu, X.; Wang, X.; Fu, J.; Zheng, J.; Liu, Y. A Novel Authentication and Key Agreement Scheme for Internet of Vehicles. Future Gener. Comput. Syst. 2023, 145, 415–428. [Google Scholar] [CrossRef] [Scilit]
- Mazhar, S.; Rakib, A.; Pan, L.; Jiang, F.; Anwar, A.; Doss, R.; Bryans, J. State-of-the-Art Authentication and Verification Schemes in VANETs: A Survey. Veh. Commun. 2024, 49, 100804. [Google Scholar] [CrossRef] [Scilit]
- Sona, G.; Purusothaman, T. A Symmetric XOR-Based Dynamic Multiple Secret Sharing Visual Cryptography Framework. Symmetry 2026, 18, 802. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM); Federal Information Processing Standards Publication FIPS 203; National Institute of Standards and Technology (NIST): Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. Module-Lattice-Based Digital Signature Standard (ML-DSA); Federal Information Processing Standards Publication FIPS 204; National Institute of Standards and Technology (NIST): Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef] [Scilit]
- Cui, J.; Liu, J.; Wei, L.; Bolodurina, I.; Li, J.; Zhong, H. Post-Quantum Secure Authenticated Key Agreement Scheme for Vehicular Digital Twin. IEEE Trans. Mob. Comput. 2026, 25, 3383–3398. [Google Scholar] [CrossRef] [Scilit]
- Paracha, M.A.; Jamil, S.U.; Shahzad, K.; Khan, M.A.; Rasheed, A. Leveraging ai for network threat detection—A conceptual overview. Electronics 2024, 13, 4611. [Google Scholar] [CrossRef] [Scilit]
- Jamil, S.U.; Khan, M.A.; Rahman, M.A.; Adeel, M.; Hussain, M. An Overview of Quantum Resistant Cybersecurity: Challenges and Future Directions. In Proceedings of the 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET), Rome, Italy, 6–9 July 2026; pp. 1–7. [Google Scholar]
- Prajapat, S.; Gautam, D.; Kumar, P.; Jangirala, S.; Das, A.K.; Park, Y.; Lorenz, P. Secure Lattice-Based Aggregate Signature Scheme for Vehicular Ad Hoc Networks. IEEE Trans. Veh. Technol. 2024, 73, 12370–12384. [Google Scholar] [CrossRef] [Scilit]
- Raja, G.; Theerthagiri, S.; Raja, K.; Ramanujam, J.A.; Sadhasivam, T.; Vasudevan, P.; Arumugam, P.; Khowaja, S.A.; Dev, K. PQAKA: Post Quantum Authentication and Key Agreement Protocol for Intelligent Internet of Vehicles over 5G. IEEE Open J. Commun. Soc. 2026, 7, 196–210. [Google Scholar] [CrossRef] [Scilit]
- Asim, M.; Wu, J.; Li, W.; Lin, Z.; Zhang, P.; He, H.; Wei, D.; Mohi-ud Din, G. Quantum-Resistant Blockchain Architecture for Secure Vehicular Networks: A ML-KEM-Enabled Approach with PoA and PoP Consensus. Future Gener. Comput. Syst. 2026, 180, 108391. [Google Scholar] [CrossRef] [Scilit]
- Sawant, S.V.; Rudra, B. QSSNET: A Quantum-Safe Distributed Trust Network Architecture for V2X Authentication and Secure Communication. Veh. Commun. 2026, 61, 101062. [Google Scholar] [CrossRef] [Scilit]
- Zou, X.; Pan, D.; Shi, G.; Yu, S.; Xie, J. V-PISL: Post-Quantum Identity-Based Signature Scheme over Lattice for VANETs. Veh. Commun. 2026, 57, 100992. [Google Scholar] [CrossRef] [Scilit]
- Rasheed, I.; Mostafa, H. DAME-IoV: Dynamic Adaptive Multi-Edge Authentication Protocol with Post-Quantum Security for Internet of Vehicles. Veh. Commun. 2025, 54, 100933. [Google Scholar] [CrossRef] [Scilit]
- Yu, X.; Wang, Y.; Huang, X. Quantum-Resistant Ring Signature-Based Authentication Scheme Against Secret Key Exposure for VANETs. Comput. Netw. 2025, 262, 111213. [Google Scholar] [CrossRef] [Scilit]
- Hsieh, W. Securing Internet of Vehicles with a Provable Secure Post-Quantum Mutually Authenticated Protocol Based on Small Integer Solution. KSII Trans. Internet Inf. Syst. 2024, 18, 3040–3059. [Google Scholar] [CrossRef] [Scilit]
- Qian, Y.; Liang, Y.; Shang, L.; Dong, X.; Liang, Y. A Key Agreement Protocol Based on a Post-Quantum Identity-Matching Scheme. Symmetry 2026, 18, 936. [Google Scholar] [CrossRef] [Scilit]
- Kozlovičs, S.; Kalniņa, E.; Vīksna, J.; Petručeņa, K.; Rencis, E. The Butterfly Protocol: Secure Symmetric Key Exchange and Mutual Authentication via Remote QKD Nodes. Symmetry 2026, 18, 153. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Wu, W.; Liang, G.; Tan, H.; Yu, Y. A Post-Quantum Authentication and Key Agreement Protocol Based on Lattice-Based KEM for Secure Network Environments. Entropy 2026, 28, 490. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Alawatugoda, J. Authenticated Key Exchange Protocol in the Standard Model under Weaker Assumptions. Cryptography 2023, 7, 1. [Google Scholar] [CrossRef] [Scilit]
- Olushola, A.; Meenakshi, S.P. Design and Implementation of an Authenticated Post-Quantum Session Protocol Using ML-KEM (Kyber), ML-DSA (Dilithium), and AES-256-GCM. Front. Phys. 2026, 13, 1723966. [Google Scholar] [CrossRef] [Scilit]
- Kumar, G.; Killi, B.R.; Das, A.K.; Park, Y. Post-Quantum Secure Lattice-Based Lightweight Authentication and Key Agreement Scheme for Multilayer IoT-Enabled Smart Grid System. IEEE Internet Things J. 2026, 13, 24604–24617. [Google Scholar] [CrossRef] [Scilit]
- Ghaban, W. Lightweight Post-Quantum Authentication and Key Agreement Protocol for Secure Smart Home IoT Control. IEEE Trans. Consum. Electron. 2026, 72, 1890–1903. [Google Scholar] [CrossRef] [Scilit]
- Guo, S.; Song, Y.; Guo, S.; Yang, Y.; Song, S. Three-Party Password Authentication and Key Exchange Protocol Based on MLWE. Symmetry 2023, 15, 1750. [Google Scholar] [CrossRef] [Scilit]
- Deng, Y.; Zhang, J.; Liu, J.; Li, J. Blockchain-Based Batch Authentication and Symmetric Group Key Agreement in MEC Environments. Symmetry 2025, 17, 2160. [Google Scholar] [CrossRef] [Scilit]
- Kim, C.; Kwon, D.K.; Park, Y.; Park, Y. Quantum-Resistant Three-Party Mutual Authentication Protocol for Industrial IoT Environments. IEEE Internet Things J. 2026, 13, 25380–25397. [Google Scholar] [CrossRef] [Scilit]
- Upadhyaya, B.; Panda, A.C.; Mohanty, S.S.; Pati, A.; Mohapatra, P. QLight-IIoT: A Quantum-Resistant Lightweight Authentication and Key Agreement Scheme for Resource-Constrained IIoT Environments. IEEE Internet Things J. 2026, 13, 27803–27815. [Google Scholar] [CrossRef] [Scilit]
- Yan, M.; Bao, Z.; Li, J.; Tian, H. Quantum-Resistant Blockchain-Assisted Certificateless Authentication and Three-Party Key Agreement Scheme for VANET. Expert Syst. Appl. 2026, 299, 130163. [Google Scholar] [CrossRef] [Scilit]
- Sharma, N.; Idrisi, M.S.; Lakshmanan, S.A. Quantum-Resistant Framework for Secure and Authorized Multi-Server Networking. Concurr. Comput. Pract. Exp. 2026, 38, e70830. [Google Scholar] [CrossRef]
- Nasiraee, H.; Nazari, F.; Samsami-Khodadad, F.; Liu, X. Neural-LWE: A Biometric-Anchored Authenticated Key Agreement for Post-Quantum Brain–Computer Interfaces. Sci. Rep. 2026, 16, 18505. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Boneh, D.; Shoup, V. A Graduate Course in Applied Cryptography, Version 0.6 Ed. Self-Published: 2023. Available online: https://toc.cryptobook.us (accessed on 10 September 2026).
- Liu, Z.; Yao, N.; Bai, S.; Mai, T. A Cooperative ECC-Based Authentication Protocol for VANETs. Sci. Rep. 2025, 15, 40837. [Google Scholar] [CrossRef] [Scilit] [PubMed]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.






