# Practical Homomorphic Authentication in Cloud-Assisted VANETs with Blockchain-Based Healthcare Monitoring for Pandemic Control

^{*}

Next Article in Journal

Next Article in Special Issue

Next Article in Special Issue

Previous Article in Journal

Department of Computer Engineering, Chosun University, Gwangju 61452, Korea

Author to whom correspondence should be addressed.

Received: 7 September 2020
/
Revised: 24 September 2020
/
Accepted: 6 October 2020
/
Published: 14 October 2020

(This article belongs to the Special Issue Wireless Sensor Networks in Intelligent Transportation Systems)

Currently, the outbreak of COVID-19 pandemic has caused catastrophic effect on every aspect of our lives, globally. The entire human race of all countries and regions has suffered devastating losses. With its high infectiousness and mortality rate, it is of great significance to carry out effective precautions and prevention of COVID-19. Specifically, the transportation system has been confirmed as one of the crucial spreading routes. Hence, enhancing healthcare monitoring and infection tracking for high-mobility transportation system is infeasible for pandemic control. Meanwhile, due to the promising advantages in the emerging intelligent transportation system (ITS), vehicular ad hoc networks (VANETs) is able to collect and process relevant vehicular data for improving the driving experience and road safety, which provide a way for non-contact automatic healthcare monitoring. Furthermore, the proliferating cloud computing and blockchain techniques enable sufficient processing and storing capabilities, along with decentralized remote auditing towards heterogenous vehicular data. In this case, the automated infection tracking for pandemic control could be achieved accordingly. For the above consideration, in this paper we develop a practical homomorphic authentication scheme for cloud-assisted VANETs, where the healthcare monitoring for all involving passengers is provided. Notably, the integrated cloud-assisted VANET infrastructure is utilized, where the hybrid medical data acquisition module is attached. In this way, timely, non-contact measurement on all passengers’ physical status can be remotely done by vehicular cloud (VC), which could also drastically improve the efficiency and guarantee safety. Vulnerabilities of the employed dedicated-short-range-communication (DSRC) technique could be properly addressed with the applied homomorphic encryption design. Additionally, the decentralized blockchain-based vehicle recording mechanism is cooperatively performed by VC and edge units. Infection tracking on specific vehicle and individual can be offered in this way. Each signature sequence is collaboratively maintained and verified by the current roadside unit (RSU) and its neighbor RSUs. The security analysis demonstrates that the proposed scheme is secure against major attacks, while the performance comparison with the state-of-the-arts relevant methods are presented for efficiency discussion.

Nowadays, the entire world is facing a severe global health crisis unlike any in the history, which is spreading human suffering and upending people’s lives. The coronavirus disease COVID-19, which is characterized as a lethal and highly infectious pandemic by the World Health Organization (WHO), has caused thousands of deaths around the world and is keeping attacking societies at their core. So far, the COVID-19 outbreak has affected all segments of population grievously and it is particularly detrimental to every social groups within the most vulnerable situations. Devastating health and economic impacts of the pandemic are being borne by everyone worldwide. When considering the high infectiousness and mortality rate, effective precautions and prevention strategies on COVID-19 is indispensable for pandemic control. Meanwhile, due to its comparatively high-density population in enclosed space and untraceable characteristics, the transportation system has been confirmed as one of the crucial spreading routes of COVID-19 [1,2]. As for public transportation tools including railway, subway, airplane, and the corresponding public locations, like airport, train station, strict detection, and surveillance mechanisms, have been adopted by most of countries so far [3]. However, infection tracking and detection for spontaneous vehicles in public highway still depends on manual work, which requires huge labor forces and financial resource [4,5,6]. Moreover, the working personnel also faces inevitable risks due to close physical contact with possible infectors.

With the urgent requirements on pandemic control, the unique advantages of vehicular ad hoc networks (VANETs) could be taken into consideration [7,8]. That is, the advanced healthcare monitoring and infection tracking, which are the two most important factors of COVID control, could be carried out by VANETs in a non-contact way. Hence, the working personnel do not need to carry out highly-risky surveillance in each checkpoint station. Instead, each RSU could be assigned as the automatic checkpoint if necessary [9,10]. On the other hand, historical route tracking towards suspected infectors is also available, provided that the sensitive medical data are uploaded to the remote VC, along with the confidential vehicle route information [11,12]. In this way, effective pandemic control strategy against COVID-19 could be achieved with VANETs. In order to provide innovative vehicular data processing and traffic management analysis, the VANET is considered as the critical component of emerging intelligent transportation system (ITS) in populous metropolitan cities and regions [13,14,15]. Generally, VANET is the distributed heterogeneous wireless network that is constructed among vehicles and roadside facilities with the functionalities of real-time dynamic vehicular data transmission [16]. VANET facilitates advanced driving security and improves the driving experience.

A fundamental VANET infrastructure is composed of road-side unit (RSU), trusted authority (TA), and terminal vehicles [17,18,19]. TA performs as the centralized service center in charge of all the corresponding system settings, such as vehicle initialization and user registration, confidential key generation [20,21]. Currently, advanced cloud computing and edge data processing techniques have been adopted, so as to provide sufficient data processing capacity for massive vehicular data [22,23]. Hence, the cloud-assisted TA is able to simultaneously manage different VANET implementations, the global Internet of Vehicles (IoV) initiatives can be achieved in this way [24,25]. The rode-side units are the distributive VANET facilities that are responsible for instant interaction with all vehicles in the vicinity. Specifically, the edge computing architecture could be utilized between RSUs with the purpose of providing low-latency and reliable data transmission with remote TA [26,27]. The edge cluster that involves neighboring RSUs collaboratively cache the frequently used vehicular data instead of requesting it from remote TA. The bandwidth burden of cloud server can be alleviated in this way. On the other hand, the vehicles are defined as the VANETs users where massive heterogenous data and driving characteristics are aggregated and forwarded for further processing [28,29,30].

VANETs enable two distinctive data transmission types: vehicle-to-RSU (V2R) and vehicle-to-vehicle (V2V). They are both powered with the 802.11p-based dedicated short-range communication (DSRC) technique [31,32,33]. V2V communication refers to the wireless data exchange of surrounding vehicles, which could help avoid crashes, ease traffic congestion, and improve the environment. The transmitted data include speed, location, direction of travel, braking, and loss of stability. V2R communication refers to the direct data interaction between each vehicle and nearby RSU. Intuitively, security and privacy protection mechanisms are of significance due to the open wireless data transmission characteristics of VANETs. That is, the transmitted vehicular data may be illegally eavesdropped or forged by adversaries, thus compromising the VANET data safety [34,35].

Nowadays, lots of studies with various safe strategies and cryptographic techniques have been made on VANET secure data transmission in order to address the VANET security issues [36,37,38]. However, the necessary parameters for practical implementation of VANET system have not yet been fully considered. When considering the globally urgent situation on COVID-19 pandemic control, potential usages and valuable applications of VANETs should be dug out. Measurements regarding VANETs and its relevant extensions should be prepared, now that the transportation system have become the one of the most dangerous scenarios for virus surveillance and infection tracking.

With the urgent motivation for automotive pandemic control, a practical homomorphic authentication scheme for cloud-assisted VANETs is developed. The proposed mechanism supports automotive healthcare monitoring and infection tracking for all involving passengers. Non-contract surveillance towards random vehicles can be remotely conducted by VC. First of all, our design applies the novel cloud-assisted VANET infrastructure with the hybrid medical data acquisition module. The WBAN layer is adopted for the integrated medical data acquisition. Notably, the essential user information on participating device is shared among edge RSU cluster. Secondly, the homomorphic encryption design is deployed for mutual authentication and key agreement. Meanwhile, the decentralized blockchain-based infection tracking mechanism on suspicious vehicles is presented. The historical route records for each vehicle can be securely preserved in VC. The signature sequence is collaboratively arranged by several RSUs at a time, offering distributive data confidentiality. Respectively, the security analysis and performance analysis are proposed, showing the superiority of the proposed scheme.

The remainder of this paper is organized, as follows. Section 2 briefly introduces the related research achievements. Section 3 illustrates the preliminary contents and relevant system settings. Section 4 presents the proposed homomorphic authentication design in cloud-assisted VANETs with blockchain-based healthcare monitoring for pandemic control. Section 5 presents the security analysis. Section 6 displays the performance analysis. The final conclusion is drawn in Section 7.

Currently, many researches on VANET secure data transmission and privacy preservation have been made, while the practical requirements for medical surveillance in practical occasions have not been fully satisfied. In 2013, a expedite message authentication protocol (EMAP) is constructed for VANET secure data transmission [17]. The efficient revocation check process is enabled with the keyed hash message authentication code (HMAC), which drastically reduces the computation burdens of certificate revocation lists (CRLs). Meanwhile, the proposed EMAP deploys the probabilistic key distribution function for confidential key sharing among non-revoked OBUs during key updating. Afterwards, a privacy-preserving authentication scheme for VANETs is developed in [21], where the designated RSUs distribute the group private information to vehicles within its arranged domain. In this case, massive vehicles can be efficiently verified without causing extensive time consumption. Chuang et al. [20] presented a decentralized trust-extended message authentication mechanism (TEAM), where the transitive trust relationships frame is utilized, so as to reduce storage consumption. Similarly, Wang et al. presented a two-factor lightweight VANETs authenticating scheme in [24], where the decentralized certificate authority (CA) and biological password are applied. The non-repudiation property for conditional tracing is achieved. In 2019, Alazzawi et al. developed a pseudo-identity-based message verification scheme [15]. Data integrity and mutual authentication can be provided. Moreover, the proposed scheme is resistant to insider attack and man-in-the-middle (MITM) attack.

Specifically, lots of schemes on vehicle conditional-privacy preserving (CPP) property have been developed. In 2010, a scalable robust authenticating method for secure VANETs transmission is proposed in [1]. Each RSU is responsible for maintaining the active vehicular groups within its vicinity. The authentic V2V broadcast is available for all participating vehicles with anonymous identities. The benign third party is involved in the relevant vehicle revocation process. The negative impact of compromised RSUs is minimized in this case. Meanwhile, system salability is provided. Thereafter, Huang et al. developed the privacy-preserving authentication scheme with conditional privacy protection. The anonymous identity for each legitimate vehicle is activated until further revocation [3]. In 2012, a dynamic key arrangement mechanism with efficient updating for location-based services (LBSs) is proposed [9]. The double registration detection design is adopted. The newly joined vehicle autonomously updates its session key for forward secrecy. Subsequently, He et al. proposed an identity-based pairing-free mutual authentication and privacy protection method [7]. Better performance and minimized computational complexity for information processing can be achieved in this way. Similarly, a two-round certificateless-based cross-domain key agreement scheme for wireless mesh networks is presented [30]. The user in previous is adomainble to prove its identity to the current domain server for session key negotiation.

Currently, the VANET scenarios with cloud computing and blockchain techniques for remote data storing and parallel processing have been studied [33,34]. In 2017, Liu et al. constructed a vehicular message safe dissemination mechanism CMDS in the cloud-assisted VANET-cellular environment [31]. Reliable and confidential data processing can be processed by the related VANET gateways and nearby vehicles. Thereafter, emphasizing on emergency message dissemination, solution to the congestion avoidance issue is proposed in the assumed vehicular fog-assisted VANET [38]. Lin et al. discussed the vehicle heterogeneity of resource allocation in the vehicular cloud computing (VCC) system [37]. Optimal strategy for VCC allocation is presented under the improved semi-Markov decision process (SMDP) model. In 2019, Ma et al. proposed an efficient pairing-free authenticated key agreement design for secure interactions in fog-based VANETs [35]. As for blockchain infrastructure in VANETs, a blockchain-assisted distributed lightweight anonymous authentication scheme with cross-datacenter interaction in vehicular fog service (VFS) is presented [4]. Similarly, in [29], with the applied Merkle Patricia tree (MPT) structure, the conventional blockchain structure is extended. Hence, the distinctive verification process without CRLs is developed. Conditional privacy preserving is achieved as well.

To be concluded, existing researches on VANETs communication either emphasize security and privacy preserving with conventional cryptographic design or construct authenticated key agreement under advanced techniques such as cloud computing and blockchain. However, the potential usages of VANETs application have not been taken full consideration for pandemic control. For this purpose, we proposed a practical homomorphic authentication scheme with the unique functionalities of healthcare surveillance and infection tracking, which is of great significance for the pandemic control towards COVID-19.

In this section, the necessary security and cryptographic concepts are respectively introduced, which include the definitions of homomorphic encryption, one-way hash function, and elliptic curve cryptosystem (ECC). Afterwards, the relevant notations of the proposed design, the novel VANET system model, and security requirements are illustrated.

With its unique properties, homomorphic encryption can be widely applied into vast security designs and privacy preserving strategies. The homomorphic encryption design allows for the predefined standard computations on ciphertexts, with which the output matches the encryption result on the computations conducted on plaintexts. Hence, the transmitted data can be securely processed and out-sourced without revealing the privacy-related information. In other words, the related homomorphic encryption and decryption functionalities can be considered as the homomorphisms between plaintext and the ciphertext spaces. In practical communication scenarios with semi-trusted entities, homomorphic encryption could remove potential privacy barriers that inhibit data sharing.

The Paillier cryptosystem [39] is defined as one of the homomorphic cryptosystems on public key infrastructure (PKI). The Paillier encryption process is additively homomorphic. That is, the product of the two ciphertexts will decrypt to the sum of their corresponding plaintexts. In this case, ${m}_{1}$, ${m}_{2}\in {\mathbb{Z}}_{n}^{*}$ are defined as the plaintexts. ${r}_{1},{r}_{2},{r}_{3}<n$ are defined as the random integers for encryption process. The following additive homomorphic properties can be satisfied:
where $\mu \in {\mathbb{Z}}_{n}^{*}$ holds. $\mathtt{E}\left(\xb7\right)$ denotes the encrypting operation.

$$\left\{\begin{array}{c}\mathtt{E}\left({m}_{1},{r}_{1}\right)\xb7\mathtt{E}\left({m}_{2},{r}_{2}\right)\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{n}^{2}=\mathtt{E}\left({m}_{1}+{m}_{2},{r}_{3}\right)\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}\phantom{\rule{3.33333pt}{0ex}}n\hfill \\ \mathtt{E}{\left({m}_{1},{r}_{1}\right)}^{\mu}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{n}^{2}=\mathtt{E}\left({m}_{1}\mu ,{r}_{3}\right)\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}\phantom{\rule{3.33333pt}{0ex}}n\hfill \end{array}\right.,$$

The security of Paillier cryptosystem is based on the decisional composite residuosity assumption (DCRA) described, as follows:

(Decisional Composite Residuosity Assumption (DCRA))**.** Define p and q as the two large primes with the condition $n=pq$. Given $\alpha \in {\mathbb{Z}}_{{n}^{2}}^{*}$, if there exist $\gamma \in {\mathbb{Z}}_{{n}^{2}}^{*}$ satisfying $\alpha \equiv {\gamma}^{n}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{n}^{2}$, α could be defined as the n-th residue modulo ${n}^{2}$. Note that, given the composite n and an integer β, it is hard to decide whether β is the n-th residue modulo ${n}^{2}$.

Define $p>3$ as a large prime and ${\mathbb{F}}_{p}$ as the finite field of order p, where $4{a}^{3}+27{b}^{2}\phantom{\rule{4.44443pt}{0ex}}(mod\phantom{\rule{0.277778em}{0ex}}p)\ne 0$ and $a,b\in {\mathbb{F}}_{p}$ [40]. In this case, ${E}_{p}\left(a,b\right)$ is defined as the the elliptic curve over the finite field ${\mathbb{F}}_{p}$, which has the following characteristic:
where $\left(x,y\right)\in {\mathbb{F}}_{p}$. The point doubling is defined as the unique addition operation on the curve ${E}_{p}\left(a,b\right)$, only if the two points are identical. Otherwise, it is called the point addition. All of the points on ${E}_{p}\left(a,b\right)$, as well as the point at infinity ∞ construct an additive Abelian group $E\left({\mathbb{F}}_{p}\right)$, where $\infty =\left(-\infty \right)$ is defined as the identity element.

$${y}^{2}={x}^{3}+ax+b\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}p,$$

(Elliptic Curve Discrete Logarithm Problem (ECDLP))**.** Define $P,Q\in {\mathbb{G}}_{1}$, where $Q=aP$. Hence, for any probabilistic polynomial-time (PPT) adversary $\mathcal{A}$, the advantage in finding the integer $a\in {\mathbb{Z}}_{q}^{*}$ to solve the ECDLP problem is defined as $Ad{v}_{\mathcal{A},{\mathbb{G}}_{1}}^{ECDLP}$, which is negligible as the following equation:

$$Ad{v}_{\mathcal{A},{\mathbb{G}}_{1}}^{ECDLP}=Pr\left(\mathcal{A}\left(P,aP\in {\mathbb{G}}_{1}\right)\to a|\forall a\in {\mathbb{Z}}_{q}^{*}\right)\le \epsilon .$$

(Computational Diffie-Hellman Problem (CDHP)). Define ${\mathbb{G}}_{1}$ as the cyclic group with the large prime order q. Given $P,aP,bP\in {\mathbb{G}}_{1}$ for $a,b\in {\mathbb{Z}}_{q}^{*}$, where P is the generator of the cyclic group ${\mathbb{G}}_{1}$. Hence, for any probabilistic polynomial-time (PPT) adversary $\mathcal{A}$, the advantage in finding computing $abP$ for solving the given CDHP problem is defined as $Ad{v}_{\mathcal{A},{\mathbb{G}}_{1}}^{CDHP}$, which is negligible as the following equation:

$$Ad{v}_{\mathcal{A},{\mathbb{G}}_{1}}^{CDHP}=Pr\left(\mathcal{A}\left(P,aP,bP\in {\mathbb{G}}_{1}\right)\to abP\in {\mathbb{G}}_{1}|\forall a,b\in {\mathbb{Z}}_{q}^{*}\right)\le \epsilon .$$

The one-way secure hash function $h(\xb7)$ is constructed with the following properties [41]:

- With a random message x of arbitrary length, the message digest of its fixed length output $h\left(x\right)$ can be easily calculated.
- It is hard to compute $x={h}^{-1}\left(y\right)$ with the given y.
- It is computationally infeasible to find ${x}^{\prime}=x$ such that $h\left({x}^{\prime}\right)=h\left(x\right)$, providing that x is given.

The notations used in our design are listed in Table 1, along with the corresponding description.

In this section, the deployed cloud-assisted VANET infrastructure with healthcare monitoring function is briefly illustrated, which can be classified into four different communication layers, including the cloud layer, edge layer, vehicle layer, and WBAN layer. The four layers with the instructions are as follows. Meanwhile, Figure 1 shows te intuitive VANET system model.

Cloud layer is considered to be the centralized data facility responsible for all of the essential system operations. Crucial system operations such as master key issuance and user registration, are all conducted by the remote cloud layer, which is defined to be trustworthy at all time. Meanwhile, massive amount of vehicular information gathered from the terminal devices is analyzed and safely stored. Particularly, the distributed cloud servers are capable of managing multiple VANET prototypes, which promotes the construction of global Internet of Vehicles (IoV) initiatives. For better description, we consider the entire cloud layer as the $\mathtt{VC}$.

Edge layer is defined as the combination of the RSU clusters, each of which is organized by direct and indirect wired connection between the nearby RSUs within predefined vicinity. Each RSU of the clusters is able to independently conduct the vehicular data interaction tasks with in-range vehicles, while the essential user information on participating devices could be shared within the cluster members. That is, collaborative computation and data processing operations for mutual authentication and message delivery could be achieved. For example, the existing cross-domain verification issue can be addressed with the applied distributive VANET edge layer, since the frequent and reliable RSU-to-RSU data exchange are assumed within RSU clusters. Practically, as for cloud-assisted VANET, low latency and high reliability characteristics of vehicle-to-RSU transmission could be satisfied with the deployed edge computing architecture (edge layer). In this case, the edge cluster involving neighboring RSUs collaboratively cache the frequently used vehicular data instead of requesting it from remote TA. The bandwidth burden of cloud server can be alleviated in this way.

Device layer refers to the terminal vehicles, where the heterogenous vehicular data and real-time road information are aggregated. Each vehicle is equipped with the embedded on-board unit (OBU) for vehicular data transmission and reception. Meanwhile, the deployed tamper-proof device (TPD) is used for confidential message preserving. Large amounts of temporary and high-speed V2V and V2R networks are continuously constructed, while complex computation cannot be carried out due to the resource limitation in vehicle side.

WBAN layer is defined as the integrated facilities for extensive medical data acquisition. VANETs with healthcare monitoring functionality can be constructed accordingly. In our assumption, all of the passengers in each vehicle are equipped with wearable device such as electronic bracelet or smart watch. The sensitive medical parameters regarding COVID-19 pandemic control can be measured and collected for subsequent test. The automotive interaction between wearable devices and the regarding vehicle is enabled, so that the pandemic factors, such as body temperature, could be remotely measured by $\mathtt{VC}$. Non-contract surveillance towards passing vehicles can be conducted in this way.

The design purpose of the proposed scheme is to improve the security properties in terms of VANET transmissions, and provide automotive healthcare monitoring for all passengers of transportation systems, so that the urgent COVID-19 pandemic control requirements can be satisfied. Consequently, the following major security characteristics for VANET security scheme are introduced.

- Conditional Privacy Preserving: considering as one of the crucial features for privacy protection, conditional privacy contains two aspects: user privacy protection and targeted vehicle information retrieving. That is, the confidential user information should be safely stored in the whole session. The illegal tracking toward specific vehicle cannot succeed. Meanwhile, the $\mathtt{VC}$ responsible for VANET system management should be able to reveal the real identity of suspect vehicle if necessary.
- Anonymity: due to the open wireless transmission features, VANET communication channels may be eavesdropped by malicious devices. Normally, messages that originated from the same device naturally carry unique data patterns. In this case, by analyzing the eavesdropped information, vital parameters, such as transmitting frequency, user location may be exposed, which severely endangers user privacy. For this consideration, the anonymity of each VANET device should be guaranteed.
- Unforgeability: in practical VANET transmission, adversary may selectively forge the valid certificates, session keys, or signatures to pass the verification process. Hence, unforgeability against chosen message attack is the major property in secure data exchange.
- Mutual Authentication: in the VANET design, mutual authentication is the fundamental but leading security property, which guarantees that both VANET entities in one communication session could authenticate each other. In this way, the impersonation attack towards certain device can be prevented.
- Non-repudiation: non-repudiation ensures the validity of the transmitted information. The message sender of VANET cannot deny the authenticity of the issued signature on the transmitted messages.
- Session Key Establishment: upon mutual authentication, the unique session key between individual vehicle and VANET system should be established, so as to provide subsequent secure data exchange.

In this section, the proposed homomorphic authentication scheme for practical VANETs is illustrated in detail. The automotive healthcare monitoring and detection strategies for all passengers of passing vehicles can be achieved. Sensitive personal medical data are locally validated and then uploaded to remote $\mathtt{VC}$ for further analysis and historical retrieving. Subsequently, the efficient infection tracking mechanism on suspected cases can be done, where the precise time-oriented travelling route of individual passenger could be retrieved. Therefore, the current practical healthcare monitoring requirements for COVID-19 pandemic control can be met. Intuitively, our design emphasizes the automotive authentication and medical data sharing in high-mobility VANET scenarios. The pairing-free certificateless cryptography is employed for key escrow resilience. User anonymity for all participating vehicles, as well as the involving passengers, are well preserved. Meanwhile, random identity updating design for various communication session is provided. Motivated by the blockchain design, the hash value for each vehicle is maintained by each RSU upon validation. Moreover, the successive RSUs could efficiently verify the correctness of the chain information by taking use of the data sharing characteristic of edge RSU clusters.

Generally, the proposed design is composed of three communicating phases: device initialization, blockchain-based key agreement, and healthcare monitoring strategy, where the workflow is shown in Figure 2. In device initialization phase, the essential vehicle, and RSU registration are preliminarily conducted. The confidential private data including the original vehicle identity and corresponding key are safely preserved in $\mathtt{VC}$. Afterwards, the mutual authentication and key distribution process between requesting vehicle and RSU is carried out in the key agreement phase, where the new vehicle is allowed to join the VANET network after interaction with $\mathtt{VC}$. The blockchain data regarding private driving records of each vehicle is updated by the RSU cluster. Finally, the healthcare monitoring strategy is presented, where the physical conditions of all involving passengers are timely surveilled and uploaded to the remote server in a secure way. Notably, the RSUs can be classified into the regular RSUs without healthcare monitoring duty, as well as the checkpoint RSU that is assigned as the checkpoint for pandemic control. Detailed introduction of all the three phases are respectively presented, as follows.

The device initialization phase is designed for system initialization and vehicle registration prior to authentication. Notably, the $\mathtt{VC}$ is defined as the validated and trustworthy entity during the whole communication session. Therefore, the crucial VANET system parameters and master key are issued and distributed by $\mathtt{VC}$. Initially, $\mathtt{VC}$ define ${\mathbb{G}}_{1}$ as the cyclic group generated by the large prime order q, where P denotes the generator of the cyclic group. Additionally, the utilized one-way hash functions ${H}_{1},{H}_{2},{H}_{3},{H}_{4},{H}_{5},{h}_{1},{h}_{2},{h}_{3},{h}_{4}$ are, respectively, performed as
In this case, the VANET system parameters set will be published in the form of $param=\left\{{\mathbb{G}}_{1},q,P,{H}_{1},{H}_{2},{H}_{3},{H}_{4},{H}_{5},{h}_{1},{h}_{2},{h}_{3},{h}_{4}\right\}$.

$$\left\{\begin{array}{c}{H}_{1}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\mathbb{G}}_{1}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {H}_{2}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\mathbb{G}}_{1}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {H}_{3}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\mathbb{G}}_{1}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {H}_{4}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {H}_{5}:{\mathbb{G}}_{1}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {h}_{1}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\mathbb{G}}_{1}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {h}_{2}:{\{0,1\}}^{*}\times {\mathbb{G}}_{1}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {h}_{3}:{\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\times {\{0,1\}}^{*}\to {\mathbb{Z}}_{q}^{*}\hfill \\ {h}_{4}:{\{0,1\}}^{*}\to {\mathbb{Z}}_{q}^{*}\hfill \end{array}\right..$$

As for individual RSU, $\mathtt{VC}$ assigns the original identity ${\mathrm{I}}_{T}^{i}\in {\{0,1\}}^{*}$ to each legitimate RSU during offline registration. The corresponded RSU secret key ${s}_{\mathbb{R}}^{i}\in {\mathbb{Z}}_{q}^{*}$ is randomly generated and distributed to RSU as well. Therefore, the confidential RSU identity set $\u2329{\mathrm{I}}_{T}^{i},{s}_{\mathbb{R}}^{i}\u232a$ is safely stored in both $\mathtt{VC}$ and RSU itself. Similarly, the initial registration process of vehicle should be conducted in advance. That is, the distinctive vehicle original identity ${\mathrm{I}}_{V}^{j}\in {\{0,1\}}^{*}$ and the corresponded vehicle secret key ${k}_{j}\in {\mathbb{Z}}_{q}^{*}$ are issued by $\mathtt{VC}$ during offline registration. The confidential vehicle identity set is defined as $\u2329{\mathrm{I}}_{V}^{j},{k}_{j}\u232a$. Note that the secure data exchange for RSU and vehicle initialization is assumed. At this point, $\mathtt{VC}$ maintains the records of all the registered RSUs and vehicles in its database. Notably, the private vehicular information, such as user name, address, social security identifier, and phone number, are stored. Table 2 shows the data structure of the vehicular records in $\mathtt{VC}$.

With the purpose of illegal tracing prevention and privacy protection, the RSU anonymous identity is created by each legitimate RSU. That is, the registered RSU randomly generates its partial secret key ${\varrho}_{\mathbb{R}}^{i}\in {\mathbb{Z}}_{q}^{*}$ and periodically extracts the time-oriented anonymous identity ${\mathrm{I}}_{\mathbb{R}}^{i}$, as
where the above $T{S}_{1}^{i}$ is referred to as the current timestamp, so that the freshness of identity can be assured. The session identity ${\mathrm{I}}_{\mathbb{R}}^{i}$ is effective only within certain time period and will expire in the subsequent time. The RSU partial secret key set $\u2329{\varrho}_{\mathbb{R}}^{i},{s}_{\mathbb{R}}^{i}\u232a$ is preserved in its storage, while ${\varrho}_{\mathbb{R}}^{i}$ is kept secret to $\mathtt{VC}$.

$${\mathrm{I}}_{\mathbb{R}}^{i}={h}_{1}\left(T{S}_{1}^{i},{\mathrm{I}}_{T}^{i},{\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\right),$$

According to the confidential information, the homomorphic encryption infrastructure can be built for each registered RSU. Initially, RSU selects two large prime ${\mathcal{M}}_{i}$ and ${\mathcal{N}}_{i}$, so that $gcd\left({\mathcal{M}}_{i}{\mathcal{N}}_{i},\left({\mathcal{M}}_{i}-1\right)\left({\mathcal{N}}_{i}-1\right)\right)=1$ holds. Subsequently, RSU randomly chooses ${\hslash}_{i}\in {\mathbb{Z}}_{{\mathcal{O}}_{i}^{2}}^{*}$ where ${\mathcal{O}}_{i}={\mathcal{M}}_{i}{\mathcal{N}}_{i}$. Hence, the computation on ${\Lambda}_{i}$ and ${\mathbb{k}}_{i}$ can be conducted according to
where ${\ell}_{i}\left(x\right)=\frac{x-1}{{\mathcal{O}}_{i}}$. At this point, the RSU homomorphic encryption key set is extracted in the form of $\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a$. Afterwards, RSU carries out the following calculations:
where $T{S}_{2}^{i}$ denotes the latest timestamp. Therefore, RSU broadcasts the parameters set $\u2329T{S}_{2}^{i},{\mathrm{I}}_{\mathbb{R}}^{i},{\mathcal{O}}_{i},{\hslash}_{i},{\mathcal{R}}^{i},{\Xi}_{\mathbb{R}}^{i}\u232a$ periodically to all devices within its range.

$$\left\{\begin{array}{c}{\Lambda}_{i}=\mathrm{lcm}\left({\mathcal{M}}_{i}-1,{\mathcal{N}}_{i}-1\right)\hfill \\ {\mathbb{k}}_{i}={\ell}_{i}\left({\hslash}_{i}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}\hfill \end{array}\right.,$$

$$\left\{\begin{array}{c}{\mathcal{R}}^{i}={\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\hfill \\ {\Xi}_{\mathbb{R}}^{i}={H}_{1}\left(T{S}_{2}^{i},{\mathrm{I}}_{\mathbb{R}}^{i},{\mathcal{O}}_{i},{\hslash}_{i},{\mathcal{R}}^{i}\right)\hfill \end{array}\right.,$$

In this section, the authentication and key management for vehicle is introduced. Initially, while assuming the vehicle with $\langle {\mathrm{I}}_{V}^{j},{k}_{j}\rangle $ is approaching the effective domain of the aforementioned RSU with anonymous identity ${\mathrm{I}}_{\mathbb{R}}^{i}$, the vehicle itself generates the random partial secret key ${\varrho}_{j}\in {\mathbb{Z}}_{q}^{*}$. In this case, the partial secret key set $\u2329{k}_{j},{\varrho}_{j}\u232a$ is stored in vehicle side. For anonymity protection, the vehicle temporary identity is applied as

$${\mathrm{I}}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{\varrho}_{j}P\right).$$

As mentioned above, vehicle is acknowledged of the broadcast RSU public information set $\u2329T{S}_{2}^{i},{\mathrm{I}}_{\mathbb{R}}^{i},{\mathcal{O}}_{i},{\hslash}_{i},{\mathcal{R}}^{i},{\Xi}_{\mathbb{R}}^{i}\u232a$. Firstly, freshness validation on the received timestamp $T{S}_{2}^{i}$ is first performed by comparing whether $\left|T{S}_{2}^{cur}-T{S}_{2}^{i}\right|\le {\epsilon}_{1}$ holds, where $T{S}_{2}^{cur}$ refers to the current timestamp. Subsequently, correctness of the certificate ${\Xi}_{\mathbb{R}}^{i}$ is verified, so as to guarantee the message integrity. Upon verification, the RSU homomorphic encryption key pair $\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a$ can be extracted by vehicle. Meanwhile, similar homomorphic encryption design for vehicle can be constructed as well. That is, the vehicle with identity ${\mathrm{I}}_{j}$ selects two large prime ${\mathcal{S}}_{j}$ and ${\mathcal{T}}_{j}$ so that $gcd\left({\mathcal{S}}_{j}{\mathcal{T}}_{j},\left({\mathcal{S}}_{j}-1\right)\left({\mathcal{T}}_{j}-1\right)\right)=1$ holds. Subsequently, vehicle randomly chooses ${\xi}_{j}\in {\mathbb{Z}}_{{\mathcal{Q}}_{j}^{2}}^{*}$, where ${\mathcal{Q}}_{j}={\mathcal{S}}_{j}{\mathcal{T}}_{j}$. Hence, the computation on ${\Gamma}_{j}$ and ${\Theta}_{j}$ can be conducted according to
where ${\varphi}_{j}\left(y\right)=\frac{y-1}{{\mathcal{Q}}_{j}}$. At this point, the vehicle homomorphic encryption key set is extracted in the form of $\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a$.

$$\left\{\begin{array}{c}{\Gamma}_{j}=\mathrm{lcm}\left({\mathcal{S}}_{j}-1,{\mathcal{T}}_{j}-1\right)\hfill \\ {\Theta}_{j}={\varphi}_{j}\left({\xi}_{j}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}\hfill \end{array}\right.,$$

Preliminarily, with the purpose of managing the historical driving information, the block chain is built in the form of $\langle {h}^{\u229b}\left(\xb7\right),{h}^{\u229b}\left(T{S}_{1}^{\u229b},{\u25ca}_{\mathbb{R}}^{i},{h}^{\u229b}\left(\xb7\right)\right),\cdots \rangle $, where ${h}^{\u229b}\left(\xb7\right)$ represents the previous hash value generated by the last encountered RSU. The entire block chain is distributively stored in $\mathtt{VC}$, while the vehicle itself stores its successive two hash values of the chain, which contains the authentication timestamp and the information of the last RSU, such as location and verification number. Notably, the vehicle does not preserve all of the chain data in storage for the consideration of inherent resource limitation, while the previous two hash values as well as the related timestamp $T{S}_{\ell -1}^{\u229b}$ for signature are enough for further validation. For better description, the two stored hash values are simplified as ${h}_{\ell -2}^{\u229b}$ and ${h}_{\ell -1}^{\u229b}$, which are generated by the previous RSU with identity ${\mathrm{I}}_{\mathbb{R}}^{i-1}$ as

$${h}_{\ell -1}^{\u229b}={h}^{\u229b}\left(T{S}_{\ell -1}^{\u229b},{\u25ca}_{\mathbb{R}}^{i-1},{h}_{\ell -2}^{\u229b}\right).$$

Upon extracting the RSU homomorphic encryption key pair $\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a$, the vehicle intends to construct the authentication process with RSU. Moreover, the previous blockchain data should also be validated and updated. Hence, the following calculations are conducted:
where the homomorphic encryption ${\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}}\left[M\right]$ is performed as
At this point, the vehicle requesting packet with its vehicle homomorphic encryption key set $\langle {\mathcal{Q}}_{j},{\xi}_{j}\rangle $ are issued as
where the blockchain information is also included.

$$\left\{\begin{array}{c}{\mathsf{{\rm Y}}}_{j}={\varrho}_{j}{\mathcal{R}}^{i}\hfill \\ {\aleph}_{j}={H}_{2}\left(T{S}_{3}^{j},{\mathrm{I}}_{V}^{j},{k}_{j}{\varrho}_{j}P\right)\hfill \\ {\Im}_{j}={H}_{3}\left(T{S}_{3}^{j},{\mathrm{I}}_{j},{\mathcal{R}}^{i},{\mathcal{Q}}_{j},{\xi}_{j},{\aleph}_{j}\right)\hfill \\ {\Xi}_{V}^{j}={\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}}\left[{\aleph}_{j}\left|\right|{\mathcal{Q}}_{j},{\xi}_{j}\left|\right|T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\left|\right|{\Im}_{j}\right]\hfill \end{array}\right.,$$

$${\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}}\left[M\right]={\hslash}_{i}^{M}\xb7{\varrho}_{j}^{{\mathcal{O}}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}.$$

$$\u2329\mathtt{Request},T{S}_{3}^{j},{\mathrm{I}}_{j},{\mathsf{{\rm Y}}}_{j},{\Xi}_{V}^{j}\u232a,$$

Upon receipt of the requesting packet, freshness verification is conducted by checking whether $\left|T{S}_{3}^{cur}-T{S}_{3}^{j}\right|\le {\epsilon}_{2}$ holds, where $T{S}_{3}^{cur}$ refers to the current timestamp. If validated, RSU is able to decrypt the received ${\Xi}_{V}^{j}$ by computing
where the RSU homomorphic decryption ${\mathtt{Dec}}_{\u2329{\mathcal{O}}_{i},{\Lambda}_{i}\u232a}^{{\mathbb{k}}_{i}}\left[C\right]$ is performed in the way of
The mathematical correctness for decryption can be illustrated as

$$\begin{array}{cc}\hfill \phantom{\rule{1.em}{0ex}}& \phantom{\rule{0.166667em}{0ex}}\phantom{\rule{0.166667em}{0ex}}\phantom{\rule{1.em}{0ex}}\u2329{\aleph}_{j}\left|\right|{\mathcal{Q}}_{j},{\xi}_{j}\left|\right|T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\left|\right|{\Im}_{j}\u232a\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\mathtt{Dec}}_{\u2329{\mathcal{O}}_{i},{\Lambda}_{i}\u232a}^{{\mathbb{k}}_{i}}\left[{\Xi}_{V}^{j}\right]\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\ell}_{i}\left({\left[{\Xi}_{V}^{j}\right]}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)}{{\mathbb{k}}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}\hfill \end{array},$$

$${\mathtt{Dec}}_{\u2329{\mathcal{O}}_{i},{\Lambda}_{i}\u232a}^{{\mathbb{k}}_{i}}\left[C\right]=\frac{{\ell}_{i}\left({C}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)}{{\mathbb{k}}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}.$$

$$\begin{array}{cc}\hfill \phantom{\rule{1.em}{0ex}}& \phantom{\rule{0.166667em}{0ex}}\phantom{\rule{0.166667em}{0ex}}\phantom{\rule{1.em}{0ex}}{\mathtt{Dec}}_{\u2329{\mathcal{O}}_{i},{\Lambda}_{i}\u232a}^{{\mathbb{k}}_{i}}\left[{\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}}\left[M\right]\right]\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\ell}_{i}\left({\left[{\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}}\left[M\right]\right]}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)}{{\mathbb{k}}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\ell}_{i}\left({\left[{\hslash}_{i}^{M}\xb7{\varrho}_{j}^{{\mathcal{O}}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right]}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)}{{\ell}_{i}\left({\hslash}_{i}^{{\Lambda}_{i}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}^{2}\right)}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =M\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{O}}_{i}\hfill \end{array}.$$

Hence, $\langle {\aleph}_{j}\left|\right|{\mathcal{Q}}_{j},{\xi}_{j}\left|\right|T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\left|\right|{\Im}_{j}\rangle $ is successfully extracted from ${\Xi}_{V}^{j}$ by RSU. The message confidentiality can be guaranteed by verifying ${\Im}_{j}$ with the acquired ${\aleph}_{j}$ and the previously broadcast ${\mathcal{R}}^{i}$ from RSU. If validated, RSU stores the vehicle homomorphic encryption key set $\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a$.

Moreover, the extensive validation procedure on blockchain should be carried out. In our assumption, upon successful authentication with certain RSU, vehicle will request RSU to verify and update its current blockchain values $\langle T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\rangle $. Dynamic information sharing among nearby RSUs is enabled, according to the aforementioned cloud-assisted VANET system model with edge RSU cluster. That is, the identity information ${\u25ca}_{\mathbb{R}}^{i-1}$ of the previous RSU will be broadcast in the way of ${\mathtt{RSU}}_{i-1}\to {\mathtt{RSU}}_{i}$. Hence, with the received ${\u25ca}_{\mathbb{R}}^{i-1}$ from RSU cluster, and the current blockchain $\langle T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\rangle $ from vehicle, ${\mathtt{RSU}}_{i}$ checks ${h}_{\ell -1}^{\u229b}\stackrel{?}{=}{h}^{\u229b}\left(T{S}_{\ell -1}^{\u229b},{\u25ca}_{\mathbb{R}}^{i-1},{h}_{\ell -2}^{\u229b}\right)$ so as to confirm the correctness of chain value. Subsequently, ${\mathtt{RSU}}_{i}$ computes ${h}_{\ell}^{\u229b}$ according to
where the $T{S}_{\ell}^{\u229b}$ denotes the current timestamp, and ${\u25ca}_{\mathbb{R}}^{i}$ is the identity information of current ${\mathtt{RSU}}_{i}$. Meanwhile, with the extracted ${\mathcal{R}}^{i}={\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P$ and ${\mathsf{{\rm Y}}}_{j}={\varrho}_{j}{\mathcal{R}}^{i}$, RSU conducts the following calculation on ${\mathsf{\Psi}}_{j}$ as

$${h}_{\ell}^{\u229b}={h}^{\u229b}\left(T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i},{h}_{\ell -1}^{\u229b}\right),$$

$$\begin{array}{cc}\hfill \phantom{\rule{1.em}{0ex}}& \phantom{\rule{0.166667em}{0ex}}\phantom{\rule{0.166667em}{0ex}}\phantom{\rule{1.em}{0ex}}{\mathsf{\Psi}}_{j}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\left({\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}\right)}^{-1}{\mathsf{{\rm Y}}}_{j}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\varrho}_{j}{\left({\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}\right)}^{-1}{\mathcal{R}}^{i}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\varrho}_{j}{\left({\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}\right)}^{-1}\left({\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}\right)P\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\varrho}_{j}P\hfill \end{array}.$$

At this point, RSU uploads $\langle T{S}_{3}^{j},{\mathrm{I}}_{j},{\mathsf{\Psi}}_{j},{\aleph}_{j},T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle $ to $\mathtt{VC}$ for the cloud verification. Notably, the vehicle identity information $\u2329{\mathrm{I}}_{V}^{j},{k}_{j}\u232a$ are stored in $\mathtt{VC}$ server. Therefore, $\mathtt{VC}$ is able to confirm the vehicle identity ${\mathrm{I}}_{V}^{j}$ with the transmitted $\langle T{S}_{3}^{j},{\mathrm{I}}_{j},{\mathsf{\Psi}}_{j},{\aleph}_{j},T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle $ from RSU. If matches, the requesting vehicle is the legitimate registered device. The vehicle access to VANET system will be granted. As for chain value updating, $\mathtt{VC}$ refreshes the stored blockchain values with the uploaded $\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle $ of ${\mathtt{RSU}}_{i}$ as well. Hence, the record $\langle {h}_{1}^{\u229b},\cdots ,{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $ is updated. The $\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle $ information is securely preserved as additional contents for further vehicle tracking. In our assumption, every time that the vehicle communicates with a new RSU, $\mathtt{VC}$ will receive confirmation message along with the crucial contents $\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle $ for chain updating. With all acquired information, $\mathtt{VC}$ is able to synchronize the decentralized blockchain values with vehicle itself, where the chain updating for vehicle is performed by the involved RSU.

Subsequently, $\mathtt{VC}$ distributes the acknowledgement message $\u2329\mathtt{Ack},{\mathrm{I}}_{j},{\delta}_{j}\u232a$ to RSU, where
Upon receiving the acknowledgement, the vehicle identity can be updated as
which includes the RSU partial key set $\u2329{\varrho}_{\mathbb{R}}^{i},{s}_{\mathbb{R}}^{i}\u232a$. In our design, the anonymous vehicle identity is safely updated as soon as the successful that verifies session is conducted. In this case, the message unlinkability for various communication sessions, and untraceability for specific vehicle, can be achieved.

$${\delta}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{k}_{j}{\varrho}_{j}P\right).$$

$${\mathrm{I}}_{j}^{1}={h}_{2}\left({\mathrm{I}}_{j},{\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\right),$$

Next, RSU is able to deliver the essential information $\langle {\delta}_{j},T{S}_{\ell}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $ to vehicle following the vehicle homomorphic encryption process with the previous vehicle key set $\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a$ and its own ${\varrho}_{\mathbb{R}}^{i}$ as
Note that the homomorphic encryption ${\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}}\left[M\right]$ can be performed as
Hence, the packet $\u2329T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j},{\mathsf{\Phi}}_{j}\u232a$ is then delivered to the destinated vehicle.

$$\left\{\begin{array}{c}{\Xi}_{\mathbb{R}}^{j}={\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}}\left[{\delta}_{j}\left|\right|T{S}_{\ell}^{\u229b}\left|\right|{h}_{\ell -1}^{\u229b}\left|\right|{h}_{\ell}^{\u229b}\right]\hfill \\ {\mathsf{\Phi}}_{j}={H}_{4}\left(T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j}\right)\hfill \end{array}\right..$$

$${\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}}\left[M\right]={\xi}_{j}^{M}\xb7{\left({\varrho}_{\mathbb{R}}^{i}\right)}^{{\mathcal{Q}}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}.$$

Upon receiving $\u2329T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j},{\mathsf{\Phi}}_{j}\u232a$, freshness confirmation is first carried out by checking whether $\left|T{S}_{4}^{cur}-T{S}_{4}^{i}\right|\le {\epsilon}_{3}$ holds, where $T{S}_{4}^{cur}$ refers to the current timestamp. Subsequently, the received ${\Xi}_{\mathbb{R}}^{j}$ can be decrypted as
where the vehicle homomorphic decryption ${\mathtt{Dec}}_{\u2329{\mathcal{Q}}_{j},{\Gamma}_{j}\u232a}^{{\Theta}_{j}}\left[C\right]$ is performed, as
Note that the mathematical correctness for the vehicle homomorphic decryption can be briefly illustrated as
At this point, ${\delta}_{j}$ can be successfully extracted from ${\Xi}_{\mathbb{R}}^{j}$. Confidentiality of the delivered packet can be confirmed by checking ${\mathsf{\Phi}}_{j}$. If validated, the vehicle conducts the final authentication, as ${\delta}_{j}\stackrel{?}{=}{h}_{2}\left({\mathrm{I}}_{V}^{j},{k}_{j}{\varrho}_{j}P\right)$.

$$\begin{array}{cc}\hfill \phantom{\rule{1.em}{0ex}}& \phantom{\rule{0.166667em}{0ex}}\phantom{\rule{0.166667em}{0ex}}\phantom{\rule{1.em}{0ex}}{\delta}_{j}\left|\right|T{S}_{\ell}^{\u229b}\left|\right|{h}_{\ell -1}^{\u229b}\left|\right|{h}_{\ell}^{\u229b}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& ={\mathtt{Dec}}_{\u2329{\mathcal{Q}}_{j},{\Gamma}_{j}\u232a}^{{\Theta}_{j}}\left[{\Xi}_{\mathbb{R}}^{j}\right]\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\varphi}_{j}\left({\left[{\Xi}_{\mathbb{R}}^{j}\right]}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)}{{\Theta}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}\hfill \end{array},$$

$${\mathtt{Dec}}_{\u2329{\mathcal{Q}}_{j},{\Gamma}_{j}\u232a}^{{\Theta}_{j}}\left[C\right]=\frac{{\varphi}_{j}\left({C}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)}{{\Theta}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}.$$

$$\begin{array}{cc}\hfill \phantom{\rule{1.em}{0ex}}& \phantom{\rule{0.166667em}{0ex}}\phantom{\rule{0.166667em}{0ex}}\phantom{\rule{1.em}{0ex}}{\mathtt{Dec}}_{\u2329{\mathcal{Q}}_{j},{\Gamma}_{j}\u232a}^{{\Theta}_{j}}\left[{\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}}\left[M\right]\right]\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\varphi}_{j}\left({\left[{\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}}\left[M\right]\right]}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)}{{\Theta}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =\frac{{\varphi}_{j}\left({\left[{\xi}_{j}^{M}\xb7{\left({\varrho}_{\mathbb{R}}^{i}\right)}^{{\mathcal{Q}}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right]}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)}{{\varphi}_{j}\left({\xi}_{j}^{{\Gamma}_{j}}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}^{2}\right)}\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}\hfill \\ \hfill \phantom{\rule{1.em}{0ex}}& =M\phantom{\rule{0.277778em}{0ex}}mod\phantom{\rule{0.277778em}{0ex}}{\mathcal{Q}}_{j}\hfill \end{array}.$$

At this point, mutual authentication between RSU and requesting vehicle is completed. In our design, the semi-trusted RSUs can perform the authentication and updating procedures without accessing the confidential vehicle secrets. Meanwhile, $s{k}_{j}={H}_{5}\left({k}_{j}{\varrho}_{j}P\right)$ is used as the shared session key established between remote $\mathtt{VC}$ and participating vehicle. In this case, the constructed homomorphic cryptographic scheme of $\left[{\mathtt{Enc}}_{\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a}^{{\varrho}_{j}},{\mathtt{Dec}}_{\u2329{\mathcal{O}}_{i},{\Lambda}_{i}\u232a}^{{\mathbb{k}}_{i}}\right]$ and $\left[{\mathtt{Enc}}_{\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a}^{{\varrho}_{\mathbb{R}}^{i}},{\mathtt{Dec}}_{\u2329{\mathcal{Q}}_{j},{\Gamma}_{j}\u232a}^{{\Theta}_{j}}\right]$ could guarantee secure and reliable data exchange. Moreover, the vehicle could also extract the updated blockchain values $\langle {h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $ and related timestamp $T{S}_{\ell}^{\u229b}$ from ${\Xi}_{\mathbb{R}}^{j}$. Hence, the previous value $\langle T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\rangle $ can be replaced with the updated $\langle T{S}_{\ell}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $. In the next authentication session with successive RSU, the newly generated $\langle T{S}_{\ell +1}^{\u229b},{h}_{\ell}^{\u229b},{h}_{\ell +1}^{\u229b}\rangle $ will be issued in the same way. The blockchain record $\langle {h}_{1}^{\u229b},\cdots ,{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b},{h}_{\ell +1}^{\u229b}\rangle $ is maintained by VC and vehicle itself, while the validation processes on successive values of the chain are operated by all of the involved RSUs. With the precise signing information $\langle T{S}_{\ell -1}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell -2}^{\u229b}\rangle $ of the encountered RSU on the road, the driving routes of particular vehicle could be securely recorded in a decentralized way. All of these strategies enable the following healthcare monitoring and infection tracking design.

With the preliminary operations introduced in the previous two phases, the healthcare monitoring strategy can be achieved, along with the infection tracking algorithm for COVID-19 pandemic control. The RSUs can be classified into regular RSUs and the checkpoint RSU, as shown in Figure 2. Regular RSU is in charge of vehicular data exchange of conventional VANETs, while the checkpoint RSUs take the responsibility of traffic surveillance and healthcare monitoring particularly. As for practical scenarios of pandemic control in transportation system, all of the regular RSUs can be selected as the checkpoint if necessary. Extensive modification on RSU hardware is not required, thus any regular RSUs can switch to checkpoint RSU easily. Therefore, effective and reliable healthcare monitoring functionality could be provided to any road sections under emergency situations. Intuitively, the above key management and mutual authentication operations are illustrated in terms of regular RSU, while the healthcare monitoring strategy in this section will be described with the assistance of checkpoint RSU. That is, real time physical status of the passengers in the passing vehicles are monitored, collected, and uploaded to $\mathtt{VC}$ at final. Additionally, the driving route information on vehicles will be attached to wearable device of individual passenger. Hence, infection tracking towards suspected persons is available.

We assume that the aforementioned vehicle is approaching the checkpoint RSU in the next (${\mathtt{RSU}}_{i}\to {\mathtt{RSU}}_{i+1}$). At this point, the vehicle possesses the essential chain values $\langle T{S}_{\ell}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $ sent by the previous ${\mathtt{RSU}}_{i}$. The blockchain-based key agreement phase is the same as above until the generation of packet $\langle T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j},{\mathsf{\Phi}}_{j}\rangle $. In the assumption of checkpoint RSU, a simple request is attached to the packet and then sent to destinated vehicle in the form of $\langle \mathtt{Request},T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j},{\mathsf{\Phi}}_{j}\rangle $. After validation, the vehicle is then aware of the request for healthcare monitoring towards its passengers.

In our assumption, the passengers in vehicles are considered to be the essential parties for healthcare monitoring in VANETs. Preliminarily, each passenger should register to $\mathtt{VC}$ in advance. Hence, the confidential identities set of the registered passengers are issued as $\{{\mathtt{cid}}_{1},\cdots ,{\mathtt{cid}}_{i}\}$, where the distributed ${\mathtt{cid}}_{i}$ is the unique original identity. The identity set $\{{\mathtt{cid}}_{1},\cdots ,{\mathtt{cid}}_{i}\}$ for all the legitimate passengers is safely stored in $\mathtt{VC}$ server. As for individual passenger, the wearable device, such as smart watch or smart bracelet, is mandatory for medical data measurement and aggregation. Moreover, with the assistance of the intra body area network (intra-BAN) and the connected medical sensors, precise and seamlessly physical data collection can be provided. Notably, each passenger and their corresponded wearable device is assumed to be the same entity with identity ${\mathtt{cid}}_{i}$.

As mentioned above, in the range of the checkpoint ${\mathtt{RSU}}_{i+1}$, the parameters set $\langle T{S}_{2}^{i+1},{\mathrm{I}}_{\mathbb{R}}^{i+1},{\mathcal{O}}_{i+1},{\hslash}_{i+1},{\mathcal{R}}^{i+1},{\Xi}_{\mathbb{R}}^{i+1}\rangle $ is periodically to all devices. Importantly, all of the wearable devices could also acquire the RSU parameters set. Hence, with the same validation and decryption process, the RSU homomorphic encryption key set $\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle $ is then acquired by passenger with ${\mathtt{cid}}_{i}$, provided that there are n passengers within one vehicle. Note that, for the n devices, the temporary identity ${\mathtt{tid}}_{i}$ is generated as ${\mathtt{tid}}_{i}=h({\mathtt{cid}}_{i},T{S}_{i}^{\oplus})$. Hence, each wearable device delivers the sensitive physical data regarding pandemic control to vehicle in the form of $En{c}_{\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle}^{{\mathtt{cid}}_{i}}\left[{\mathtt{tid}}_{i},data\right]$. The vehicle then gathers all n packets from different passengers and forwards it to RSU in the form of

$$En{c}_{\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle}^{{\varrho}_{j}}\left[En{c}_{\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle}^{{\mathtt{cid}}_{1}}\left[{\mathtt{tid}}_{1},data\right],\cdots ,En{c}_{\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle}^{{\mathtt{cid}}_{n}}\left[{\mathtt{tid}}_{n},data\right]\right].$$

RSU can then decrypt the identities ${\mathtt{tid}}_{i}$ and medical data from the passengers. If unique patterns are detected, then RSU sends the warning report to $\mathtt{VC}$ and request for retransmission. Eventually, the gathered healthcare data, along with the current RSU information ${\u25ca}_{\mathbb{R}}^{i+1}$, are uploaded to $\mathtt{VC}$ and stored for further usage. In the further time, if certain passenger is infected, its historical healthcare record and route information can be retrieved in the $\mathtt{VC}$ database, the infection tracking method is accordingly available, which is of great significance for pandemic control.

In this section, the major security characteristics of the proposed design are discussed, respectively. Moreover, comparisons with the existing methods in terms of the VANET authentication and key management are presented.

The authentication process is proven to be correct if and only if the certificates are successfully issued following the device registration and authentication strategy.

Initially, the specific vehicle with $\langle {\mathrm{I}}_{V}^{j},{k}_{j}\rangle $ approaches the regular RSU with original identity set $\langle {\mathrm{I}}_{T}^{1},{s}_{\mathbb{R}}^{1}\rangle $. RSU itself issues the public parameter set $\langle T{S}_{2}^{1},{\mathrm{I}}_{\mathbb{R}}^{1},{\mathcal{O}}_{1},{\hslash}_{1},{\mathcal{R}}^{1},{\Xi}_{\mathbb{R}}^{1}\rangle $, where
With the assigned vehicle homomorphic encryption mechanism $En{c}_{\langle {\mathcal{O}}_{1},{\hslash}_{1}\rangle}^{{\varrho}_{j}}\left[M\right]={\hslash}_{1}^{M}\xb7{\varrho}_{j}^{{\mathcal{O}}_{1}}\mathtt{mod}{\mathcal{O}}_{1}^{2}$, $\langle \mathtt{Request},T{S}_{3}^{j},{\mathrm{I}}_{j},{\mathsf{{\rm Y}}}_{j},{\Xi}_{V}^{j}\rangle $ can be generated by vehicle in the form of ${\Xi}_{V}^{j}=En{c}_{\langle {\mathcal{O}}_{1},{\hslash}_{1}\rangle}^{{\varrho}_{j}}\left[{\aleph}_{j}\parallel {\mathcal{Q}}_{j},{\xi}_{j}\parallel {\Im}_{j}\right]$. At this point, the blockchain has not been generated, since it is in the first RSU range. Upon receiving the confirmation message from remote $\mathtt{VC}$, RSU computes ${h}_{1}^{\u229b}={h}^{\u229b}\left(T{S}_{1}^{\u229b},{\u25ca}_{\mathbb{R}}^{1}\right)$, where $T{S}_{1}^{\u229b}$ denotes the current timestamp, and ${\u25ca}_{\mathbb{R}}^{1}$ is the identity information of current ${\mathtt{RSU}}_{i}$. Note that the crucial contents $\langle T{S}_{1}^{\u229b},{\u25ca}_{\mathbb{R}}^{1}\rangle $ is uploaded to $\mathtt{VC}$ for chain updating. Only with the delivered acknowledgement message $\langle Ack,{\mathrm{I}}_{j},{\delta}_{j}\rangle $ from $\mathtt{VC}$, the RSU is able to legitimately pass the verification process ${\delta}_{j}\stackrel{?}{=}{h}_{2}\left({\mathrm{I}}_{V}^{j},{k}_{j}{\varrho}_{j}P\right)$ in vehicle side. Similarly, in the next authentication session of second RSU with $\langle {\mathrm{I}}_{T}^{2},{s}_{\mathbb{R}}^{2}\rangle $, the $\mathtt{VC}$ hash chain is updated as $\langle {h}_{1}^{\u229b},{h}_{2}^{\u229b}\rangle $, where ${h}_{2}^{\u229b}={h}^{\u229b}\left(T{S}_{2}^{\u229b},{\u25ca}_{\mathbb{R}}^{2},{h}_{1}^{\u229b}\right)$. Following this way, in the ℓ session, RSU is able to deliver the essential information $\langle {\delta}_{j},T{S}_{\ell}^{\u229b},{h}_{\ell -1}^{\u229b},{h}_{\ell}^{\u229b}\rangle $ to vehicle following the vehicle homomorphic encryption process. Note that ${\delta}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{k}_{j}{\varrho}_{j}P\right)$ holds, Assuming the length of partial secrets $\langle {k}_{j},{\varrho}_{j}\rangle $ is t, respectively. Hence, the probability to successfully pass the validation process is $\frac{1}{{4}^{t}}$. The correctness of our design can be proven. □

$$\left\{\begin{array}{c}{\mathrm{I}}_{\mathbb{R}}^{1}={h}_{1}\left(T{S}_{1}^{1},{\mathrm{I}}_{T}^{1},{\varrho}_{\mathbb{R}}^{1}{s}_{\mathbb{R}}^{1}P\right)\hfill \\ {\Lambda}_{1}=\mathrm{lcm}\left({\mathcal{M}}_{1}-1,{\mathcal{N}}_{1}-1\right)\hfill \\ {\mathcal{R}}^{1}={\varrho}_{\mathbb{R}}^{1}{s}_{\mathbb{R}}^{1}P\hfill \\ {\Xi}_{\mathbb{R}}^{1}={H}_{1}\left(T{S}_{2}^{1},{\mathrm{I}}_{\mathbb{R}}^{1},{\mathcal{O}}_{1},{\hslash}_{1},{\mathcal{R}}^{1}\right)\hfill \end{array}\right..$$

Message unlinkability within various RSUs effective range can be achieved. Moreover, dynamic chain updating is performed upon each successful validation.

Assuming specific vehicle with route ${\mathtt{RSU}}_{1}\to {\mathtt{RSU}}_{n}$ is in the i-th RSU domain ($i\in [1,n]$), the vehicle with $\langle {\mathrm{I}}_{V}^{j},{k}_{j}\rangle $ utilizes the temporary identity ${\mathrm{I}}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{\varrho}_{j}P\right)$, where the random partial secret key is adopted. Note that the temporary identity varies for different sessions. Furthermore, upon receiving the acknowledgement at final step, the vehicle identity can be updated as ${\mathrm{I}}_{j}^{1}={h}_{2}\left({\mathrm{I}}_{j},{\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\right)$. The delivered packet from RSU is $\langle T{S}_{4}^{i},{\mathrm{I}}_{j}^{1},{\Xi}_{\mathbb{R}}^{j},{\mathsf{\Phi}}_{j}\rangle $. That is, dynamic vehicle identities are used in the same authentication session, which significantly prevents information eavesdropping and tracing. Unlinkability on the confidential vehicular data during transmission can be provided as well. Additionally, the vehicle does not preserve all of the chain data in storage for the consideration of inherent resource limitation, while the previous chain values denoted as ${h}_{\ell -2}^{\u229b}$ and ${h}_{\ell -1}^{\u229b}$ are stored for chain validation and updating. Note that the previous RSU calculates ${h}_{\ell -1}^{\u229b}={h}^{\u229b}\left(T{S}_{\ell -1}^{\u229b},{\u25ca}_{\mathbb{R}}^{i-1},{h}_{\ell -2}^{\u229b}\right)$. With the constructed homomorphic encryption strategy, the chain values can be managed by each encountered RSU in a decentralized way. Specifically, the vehicle and each RSU share the two successive chain values, while $\mathtt{VC}$ preserves the integrated blockchain for further usage. □

Conditional identity privacy preservation for vehicle and RSUs is achieved. Untraceability towards specific vehicle is guaranteed, while the remote VC is capable of retrieving the real identity of certain vehicle under extreme situations.

In the device initialization phase, the registered RSU randomly generates its partial secret key ${\varrho}_{\mathbb{R}}^{i}\in {\mathbb{Z}}_{q}^{*}$ and periodically extracts the time-oriented anonymous identity ${\mathrm{I}}_{\mathbb{R}}^{i}$ as ${\mathrm{I}}_{\mathbb{R}}^{i}={h}_{1}\left(T{S}_{1}^{i},{\mathrm{I}}_{T}^{i},{\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\right)$, where the random partial secret key set $\langle {\varrho}_{\mathbb{R}}^{i},{s}_{\mathbb{R}}^{i}\rangle $, along with the current timestamp $T{S}_{1}^{i}$ is applied. Similarly, for anonymity protection, the vehicle temporary identity is applied as ${\mathrm{I}}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{\varrho}_{j}P\right)$ and ${\mathrm{I}}_{j}^{1}={h}_{2}\left({\mathrm{I}}_{j},{\varrho}_{\mathbb{R}}^{i}{s}_{\mathbb{R}}^{i}P\right)$, respectively. Note that the distinctive identity ${\mathrm{I}}_{V}^{j}\in {\{0,1\}}^{*}$ and ${\mathrm{I}}_{T}^{i}\in {\{0,1\}}^{*}$ remain hidden all of the time. Each ${\mathrm{I}}_{\mathbb{R}}^{i}$ is only effective within a certain time period and will expire periodically. In this way, anonymous identities for both RSUs and vehicles are provided. Privacy preservation property is provided in this way. Meanwhile, the entire block chain regarding driving route and real identity is safely stored in $\mathtt{VC}$. Therefore, $\mathtt{VC}$ is able to reveal the original identity of all RSUs or vehicles, which is crucial for detecting and revoking the compromised VANET entities. Accordingly, conditional identity privacy preserving is provided. □

Replay attacking resistance is provided during the whole authentication process. Reusage of the previous information from past authentication sessions cannot pass the current validation.

In the device initialization phase and key agreement phase, the fresh timestamps are widely used in each calculation. Meanwhile, the certificates with all transmitted elements are presented so as to guarantee data integrity. As mentioned above, the RSU public information set is broadcast in the form of $\langle T{S}_{2}^{i},{\mathrm{I}}_{\mathbb{R}}^{i},{\mathcal{O}}_{i},{\hslash}_{i},{\mathcal{R}}^{i},{\Xi}_{\mathbb{R}}^{i}\rangle $, where the latest time stamp is included. In the subsequent authentication session, the vehicle calculates the certificate ${\Xi}_{V}^{j}=En{c}_{\langle {\mathcal{O}}_{i},{\hslash}_{i}\rangle}^{{\varrho}_{j}}\left[{\aleph}_{j}\left|\right|{\mathcal{Q}}_{j},{\xi}_{j}\left|\right|{\Im}_{j}\right]$ according to the intermediate values $\langle {\aleph}_{j},{\Im}_{j}\rangle $, which is related to the timestamp $T{S}_{3}^{j}$. In this case, provided that, in specific moment ${\mathbb{T}}_{\mathcal{A}}$, the adversary ${\mathcal{A}}_{1}$ is able to collect z transmitted packets ${\langle \mathtt{Request},T{S}_{3}^{l},{\mathrm{I}}_{l},{\mathsf{{\rm Y}}}_{l},{\Xi}_{V}^{l}\rangle}_{l\in \left[1,z\right]}$ during certain time interval $\left[{\mathbb{T}}_{\mathcal{H}},{\mathbb{T}}_{\mathcal{C}}\right]$ (${\mathbb{T}}_{\mathcal{C}}<{\mathbb{T}}_{\mathcal{A}}$). Intuitively, the probability for ${\Xi}_{V}^{\mathcal{A}}$ to pass the verification is $\frac{z}{{2}^{t}}$, where the length of output ${\Xi}_{V}^{\mathcal{A}}$ is assumed to be t. Therefore, our design has proved to be resistant to replay attack. □

Certificateless authentication design is deployed in the proposed authentication session. No-repudiation characteristic is provided for vehicles.

In the aforementioned device initialization phase, the original identity for vehicle is assigned as ${\mathrm{I}}_{V}^{j}$, while the assigned secret key ${k}_{j}$ is safely shared among $\mathtt{VC}$ and vehicle. Meanwhile, the vehicle itself randomly generates the partial key ${\varrho}_{j}\in {\mathbb{Z}}_{q}^{*}$ and keeps it secret to $\mathtt{VC}$. Therefore, with the characteristics of ECDLP, it is difficult to extract ${\varrho}_{j}$ from the published ${\mathrm{I}}_{j}={h}_{2}\left({\mathrm{I}}_{V}^{j},{\varrho}_{j}P\right)$ or ${\mathsf{{\rm Y}}}_{j}={\varrho}_{j}{\mathcal{R}}^{i}$. The impersonation towards specific vehicle cannot be accepted by the receiver. Similarly, the RSU partial secret key ${\varrho}_{\mathbb{R}}^{i}\in {\mathbb{Z}}_{q}^{*}$ is randomly generated by RSU and kept hidden to $\mathtt{VC}$. Therefore, $\mathtt{VC}$ does not have full control over the participating vehicles and RSUs. Hence, the certificateless authentication property is provided. □

In this section, the security properties comparison with existing VANETs secure communication is presented. The proposed protocol is compared with the state-of-the-art authentication and key management methods: AKMB [42], IBCPA [7], and EPCBV [43] in order to demonstrate its superiority on security properties. The comparison results presented in Table 3 show that the proposed scheme could meet the desirable security requirements that are introduced in Section 3.6.

In this section, the performance of the proposed scheme is discussed, which specifically emphasizes on the crucial properties for resource-limited VANETs environment, such as storage overhead andcomputation cost.

In practical environment, the VANET entities, including vehicles and RSUs, are the fundamental units in V2V and V2R wireless communication. Due to the resource restriction, the storage overhead required for the authentication process should be optimized. The state-of-the-art VANETs authentication schemes, including AKMB [42], IBCPA [7], and EPCBV [43] are also analyzed. Hence, the advantages of our scheme on storage overhead can be demonstrated as shown in Figure 3, where the storage cost for individual RSU is presented. Obviously, less storage overhead is required in the proposed scheme.

In this section, the computation cost of the proposed design is analyzed. The time consumption for authentication in RSU side is discussed in terms of the number of participating vehicles. Note that the complex pairing calculations are not adopted in our design. The comparison results with AKMB [42], IBCPA [7], and EPCBV [43] are presented in Figure 4. Intuitively, less time consumption is required for authenticating process with resource limited vehicles, which proves the performance advantages of our design.

In this paper, emphasizing automotive pandemic control in intelligent transportation system, a practical homomorphic authentication method for healthcare monitoring in cloud-assisted VANETs is developed. In the proposed scheme, medical surveillance and infection tracking towards suspected passengers can be achieved. Our design applies the novel cloud infrastructure with the hybrid medical data acquisition module. Non-contract surveillance towards random vehicles can be remotely conducted by vehicular cloud. Moreover, the decentralized blockchain-based route recording mechanism is enabled, where the accurate and timely route information for each involved vehicle can be securely uploaded and analyzed in VC. The chain updating operations are collaboratively conducted by several decentralized RSU edge entities at a time, so that vehicular data confidentiality is guaranteed. Analysis on the featured security properties and comparison with other schemes prove that our design can meet the practical security requirements. Meanwhile, performance analysis with other studies show its efficiency. With these unique advantages, the proposed design can be utilized for the current COVID-19 pandemic control.

Conceptualization, H.T. and I.C.; Methodology, H.T.; Formal analysis, H.T.; Investigation, P.K.; Writing—Original Draft Preparation, H.T.; Writing—Review and Editing, H.T. and I.C.; Supervision, I.C. All authors have read and agreed to the published version of the manuscript.

This work was supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIT) (No. NRF-2020R1A2C2007091).

The authors declare no conflict of interest.

- Zhang, L.; Wu, Q.; Solanas, A.; Domingo-Ferrer, J. A Scalable Robust Authentication Protocol for Secure Vehicular Communications. IEEE Trans. Veh. Technol.
**2010**, 59, 1606–1617. [Google Scholar] [CrossRef] - Kaur, K.; Garg, S.; Kaddoum, G.; Gagnon, F.; Ahmed, S.H. Blockchain-Based Lightweight Authentication Mechanism for Vehicular Fog Infrastructure. In Proceedings of the 2019 IEEE International Conference on Communications Workshops (ICC Workshops), Shanghai, China, 20–24 May 2019; pp. 1–6. [Google Scholar]
- Huang, D.; Misra, S.; Verma, M.; Xue, G. PACP: An Efficient Pseudonymous Authentication-Based Conditional Privacy Protocol for VANETs. IEEE Trans. Intell. Transp. Syst.
**2011**, 12, 736–746. [Google Scholar] [CrossRef] - Yao, Y.; Chang, X.; Mišić, J.; Mišić, V.B.; Li, L. BLA: Blockchain-Assisted Lightweight Anonymous Authentication for Distributed Vehicular Fog Services. IEEE Internet Things J.
**2019**, 6, 3775–3784. [Google Scholar] [CrossRef] - Tan, H.; Chung, I. Secure Authentication and Group Key Distribution Scheme for WBANs Based on Smartphone ECG Sensor. IEEE Access
**2019**, 7, 151459–151474. [Google Scholar] [CrossRef] - Li, J.; Lu, H.; Guizani, M. ACPN: A Novel Authentication Framework with Conditional Privacy-Preservation and Non-Repudiation for VANETs. IEEE Trans. Parallel Distrib. Syst.
**2015**, 26, 938–948. [Google Scholar] [CrossRef] - He, D.; Zeadally, S.; Xu, B.; Huang, X. An Efficient Identity-Based Conditional Privacy-Preserving Authentication Scheme for Vehicular Ad Hoc Networks. IEEE Trans. Inf. Forensics Secur.
**2015**, 10, 2681–2691. [Google Scholar] [CrossRef] - Lo, N.; Tsai, J. An Efficient Conditional Privacy-Preserving Authentication Scheme for Vehicular Sensor Networks Without Pairings. IEEE Trans. Intell. Transp. Syst.
**2016**, 17, 1319–1328. [Google Scholar] [CrossRef] - Lu, R.; Lin, X.; Liang, X.; Shen, X. A Dynamic Privacy-Preserving Key Management Scheme for Location-Based Services in VANETs. IEEE Trans. Intell. Transp. Syst.
**2012**, 13, 127–139. [Google Scholar] [CrossRef] - Tan, H.; Choi, D.; Kim, P.; Pan, S.; Chung, I. Secure Certificateless Authentication and Road Message Dissemination Protocol in VANETs. Wirel. Commun. Mob. Comput.
**2018**, 2018, 1–13. [Google Scholar] [CrossRef] - Shao, J.; Lin, X.; Lu, R.; Zuo, C. A Threshold Anonymous Authentication Protocol for VANETs. IEEE Trans. Veh. Technol.
**2016**, 65, 1711–1720. [Google Scholar] [CrossRef] - Zhang, Q.; Gan, Y.; Zhang, Q.; Wang, R.; Tan, Y. A Dynamic and Cross-Domain Authentication Asymmetric Group Key Agreement in Telemedicine Application. IEEE Access
**2018**, 6, 24064–24074. [Google Scholar] - Tian, Z.; Shi, W.; Wang, Y.; Zhu, C.; Du, X.; Su, S.; Sun, Y.; Guizani, N. Real-Time Lateral Movement Detection Based on Evidence Reasoning Network for Edge Computing Environment. IEEE Trans. Ind. Inform.
**2019**, 15, 4285–4294. [Google Scholar] [CrossRef] - Tan, H.; Choi, D.; Kim, P.; Pan, S.; Chung, I. An Efficient Hash-based RFID Grouping Authentication Protocol Providing Missing Tags Detection. J. Internet Technol.
**2018**, 19, 481–488. [Google Scholar] - Alazzawi, M.A.; Lu, H.; Yassin, A.A.; Chen, K. Efficient Conditional Anonymity With Message Integrity and Authentication in a Vehicular Ad-Hoc Network. IEEE Access
**2019**, 7, 71424–71435. [Google Scholar] [CrossRef] - Hao, Y.; Cheng, Y.; Zhou, C.; Song, W. A Distributed Key Management Framework with Cooperative Message Authentication in VANETs. IEEE J. Sel. Areas Commun.
**2011**, 29, 616–629. [Google Scholar] [CrossRef] - Wasef, A.; Shen, X. EMAP: Expedite Message Authentication Protocol for Vehicular Ad Hoc Networks. IEEE Trans. Mob. Comput.
**2013**, 12, 78–89. [Google Scholar] [CrossRef] - Tan, H.; Chung, I. A Secure and Efficient Group Key Management Protocol with Cooperative Sensor Association in WBANs. Sensors
**2018**, 18, 3930. [Google Scholar] [CrossRef] - He, D.; Kumar, N.; Wang, H.; Wang, L.; Choo, K.R.; Vinel, A. A Provably-Secure Cross-Domain Handshake Scheme with Symptoms-Matching for Mobile Healthcare Social Network. IEEE Trans. Dependable Secur. Comput.
**2018**, 15, 633–645. [Google Scholar] [CrossRef] - Chuang, M.; Lee, J. TEAM: Trust-Extended Authentication Mechanism for Vehicular Ad Hoc Networks. IEEE Syst. J.
**2014**, 8, 749–758. [Google Scholar] [CrossRef] - Zhu, X.; Jiang, S.; Wang, L.; Li, H. Efficient Privacy-Preserving Authentication for Vehicular Ad Hoc Networks. IEEE Trans. Veh. Technol.
**2014**, 63, 907–919. [Google Scholar] [CrossRef] - Shen, J.; Tan, H.; Ren, Y.; Liu, Q.; Wang, B. A Practical RFID Grouping Authentication Protocol in Multiple-Tag Arrangement With Adequate Security Assurance. In Proceedings of the 2016 18th International Conference on Advanced Communication Technology (ICACT), Pyeongchang, Korea, 31 January–3 February 2016; pp. 693–699. [Google Scholar]
- Tan, H.; Chung, I. A Secure Cloud-Assisted Certificateless Group Authentication Scheme for VANETs in Big Data Environment. In Proceedings of the 2019 International Conference on Big Data Engineering (BDE2019), Hong Kong, China, 11–13 June 2019; pp. 107–113. [Google Scholar]
- Wang, F.; Xu, Y.; Zhang, H.; Zhang, Y.; Zhu, L. 2FLIP: A Two-Factor Lightweight Privacy-Preserving Authentication Scheme for VANET. IEEE Trans. Veh. Technol.
**2016**, 65, 896–911. [Google Scholar] [CrossRef] - Tan, H.; Song, Y.; Xuan, S.; Pan, S.; Chung, I. Secure D2D Group Authentication Employing Smartphone Sensor Behavior Analysis. Symmetry
**2018**, 11, 969. [Google Scholar] [CrossRef] - Feng, Q.; He, D.; Zeadally, S.; Liang, K. BPAS: Blockchain-Assisted Privacy-Preserving Authentication System for Vehicular Ad Hoc Networks. IEEE Trans. Ind. Inform.
**2020**, 16, 4146–4155. [Google Scholar] [CrossRef] - Zhou, T.; Shen, J.; Li, X.; Wang, C.; Tan, H. Logarithmic Encryption Scheme for Cyber-Physical Systems Employing Fibonacci Q-matrix. Future Gener. Comput. Syst.
**2020**, 108, 1307–1313. [Google Scholar] [CrossRef] - Tan, H.; Xuan, S.; Chung, I. HCDA: Efficient Pairing-Free Homographic Key Management for Dynamic Cross-Domain Authentication in VANETs. Symmetry
**2020**, 12, 1003. [Google Scholar] [CrossRef] - Lu, Z.; Wang, Q.; Qu, G.; Zhang, H.; Liu, Z. A Blockchain-Based Privacy-Preserving Authentication Scheme for VANETs. IEEE Trans. Very Large Scale Integr. (VLSI) Syst.
**2019**, 27, 2792–2801. [Google Scholar] [CrossRef] - Li, Y.; Chen, W.; Cai, Z.; Fang, Y. CAKA: A Novel Certificateless-Based Cross-Domain Authenticated Key Agreement Protocol for Wireless Mesh Networks. Wirel. Netw.
**2016**, 22, 2523–2535. [Google Scholar] [CrossRef] - Liu, B.; Jia, D.; Wang, J.; Lu, K.; Wu, L. Cloud-Assisted Safety Message Dissemination in VANET–Cellular Heterogeneous Wireless Network. IEEE Syst. J.
**2017**, 11, 128–139. [Google Scholar] [CrossRef] - Tan, H.; Gui, Z.; Chung, I. A Secure and Efficient Certificateless Authentication Scheme With Unsupervised Anomaly Detection in VANETs. IEEE Access
**2018**, 6, 74260–74276. [Google Scholar] [CrossRef] - Wang, Y.; Ding, Y.; Wu, Q.; Wei, Y.; Qin, B.; Wang, H. Privacy-Preserving Cloud-Based Road Condition Monitoring With Source Authentication in VANETs. IEEE Trans. Inf. Forensics Secur.
**2019**, 14, 1779–1790. [Google Scholar] [CrossRef] - Cui, J.; Wei, L.; Zhang, J.; Xu, Y.; Zhong, H. An Efficient Message-Authentication Scheme Based on Edge Computing for Vehicular Ad Hoc Networks. IEEE Trans. Intell. Transp. Syst.
**2019**, 20, 1621–1632. [Google Scholar] [CrossRef] - Ma, M.; He, D.; Wang, H.; Kumar, N.; Choo, K.R. An Efficient and Provably Secure Authenticated Key Agreement Protocol for Fog-Based Vehicular Ad-Hoc Networks. IEEE Internet Things J.
**2019**, 6, 8065–8075. [Google Scholar] [CrossRef] - Tan, H.; Choi, D.; Kim, P.; Pan, S.; Chung, I. Comments on ‘Dual Authentication and Key Management Techniques for Secure Data Transmission in Vehicular Ad Hoc Networks’. IEEE Trans. Intell. Transp. Syst.
**2017**, 19, 2149–2151. [Google Scholar] [CrossRef] - Lin, C.; Deng, D.; Yao, C. Resource Allocation in Vehicular Cloud Computing Systems With Heterogeneous Vehicles and Roadside Units. IEEE Internet Things J.
**2018**, 5, 3692–3700. [Google Scholar] [CrossRef] - Ullah, A.; Yaqoob, S.; Imran, M.; Ning, H. Emergency Message Dissemination Schemes Based on Congestion Avoidance in VANET and Vehicular FoG Computing. IEEE Access
**2019**, 7, 1570–1585. [Google Scholar] [CrossRef] - Paillier, P. Public-Key Cryptosystems Based on Composite Degree Residuosity Classes. In Advances in Cryptology—EUROCRYPT ’99; Springer: Berlin/Heidelberg, Germany, 1999; pp. 223–238. [Google Scholar]
- Smart, N.P. The Discrete Logarithm Problem on Elliptic Curves of Trace One. J. Cryptol.
**1999**, 12, 193–196. [Google Scholar] [CrossRef] - Merkle, R.C. A Fast Software One-way Hash Function. J. Cryptol.
**1990**, 3, 43–58. [Google Scholar] [CrossRef] - Tan, H.; Chung, I. Secure Authentication and Key Management With Blockchain in VANETs. IEEE Access
**2020**, 8, 2482–2498. [Google Scholar] [CrossRef] - Gayathri, N.B.; Thumbur, G.; Reddy, P.V.; Muhammad, Z.U.R. Efficient Pairing-Free Certificateless Authentication Scheme With Batch Verification for Vehicular Ad-Hoc Networks. IEEE Access
**2018**, 6, 31808–31819. [Google Scholar] [CrossRef]

Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. |

Symbol | Description |
---|---|

$\mathtt{VC}$, $\{{\mathtt{RSU}}_{1},\cdots ,{\mathtt{RSU}}_{n}\}$ | Vehicular Cloud, Road-Side Units |

${\mathrm{I}}_{V}^{j},{\mathrm{I}}_{j},{\mathrm{I}}_{j}^{k}$ | Vehicle Identities |

${\mathbb{G}}_{1}$ | Cyclic Group |

P | Generator of ${\mathbb{G}}_{1}$ |

${\mathrm{I}}_{T}^{i},{\mathrm{I}}_{\mathbb{R}}^{i}$ | ${\mathtt{RSU}}_{i}$ Identities |

$\u2329{\mathcal{Q}}_{j},{\xi}_{j}\u232a$ | Vehicle Encryption Key Set |

$\u2329{\Gamma}_{j},{\Theta}_{j}\u232a$ | Vehicle Decryption Key Set |

$\u2329{\varrho}_{\mathbb{R}}^{i},{s}_{\mathbb{R}}^{i}\u232a$ | ${\mathtt{RSU}}_{i}$ Partial Secret Key Set |

$\u2329{\mathcal{O}}_{i},{\hslash}_{i}\u232a$ | ${\mathtt{RSU}}_{i}$ Encryption Key Set |

$\u2329{\Lambda}_{i},{\mathbb{k}}_{i}\u232a$ | ${\mathtt{RSU}}_{i}$ Decryption Key Set |

${\mathcal{M}}_{i},{\mathcal{N}}_{i},{\mathcal{S}}_{j},{\mathcal{T}}_{j}$ | Large Prime Values |

$\u2329{k}_{j},{\varrho}_{j}\u232a$ | Vehicle Partial Secret Key Set |

${\u25ca}_{\mathbb{R}}^{i}$ | ${\mathtt{RSU}}_{i}$ Additional Information |

$\{{h}_{1}^{\u229b},\cdots {h}_{\ell}^{\u229b}\}$ | Route Records |

No. | Original Identity Set | Location | Name/Addr./SSN/ | Route Info. | Add. Info. | |
---|---|---|---|---|---|---|

Type | ||||||

RSU | 1 | $\langle {\mathrm{I}}_{T}^{1},{s}_{\mathbb{R}}^{1}\rangle $ | ◯ | ∖ | ∖ | ${\u25ca}_{\mathbb{R}}^{1}$ |

2 | $\langle {\mathrm{I}}_{T}^{2},{s}_{\mathbb{R}}^{2}\rangle $ | ◯ | ∖ | ∖ | ${\u25ca}_{\mathbb{R}}^{2}$ | |

⋯ | ⋯ | ⋯ | ⋯ | ⋯ | ⋯ | |

i | $\langle {\mathrm{I}}_{T}^{i},{s}_{\mathbb{R}}^{i}\rangle $ | ◯ | ∖ | ∖ | ${\u25ca}_{\mathbb{R}}^{i}$ | |

Vehicle | 1 | $\langle {\mathrm{I}}_{V}^{1},{k}_{1}\rangle $ | ∖ | ◯ | $\left\{{h}_{1}^{\u229b},{h}_{2}^{\u229b},\cdots \right\}$ | $\left[\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle ,\cdots \right]$ |

2 | $\langle {\mathrm{I}}_{V}^{2},{k}_{2}\rangle $ | ∖ | ◯ | $\left\{{h}_{1}^{\u229b},{h}_{2}^{\u229b},\cdots \right\}$ | $\left[\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle ,\cdots \right]$ | |

⋯ | ⋯ | ⋯ | ⋯ | ⋯ | ⋯ | |

j | $\langle {\mathrm{I}}_{V}^{j},{k}_{j}\rangle $ | ∖ | ◯ | $\left\{{h}_{1}^{\u229b},{h}_{2}^{\u229b},\cdots \right\}$ | $\left[\langle T{S}_{\ell}^{\u229b},{\u25ca}_{\mathbb{R}}^{i}\rangle ,\cdots \right]$ | |

Passenger | 1 | ${\mathtt{cid}}_{1}$ | ∖ | ◯ | $\{{\u25ca}_{\mathbb{R}}^{i},\cdots \}$ | ∖ |

2 | ${\mathtt{cid}}_{2}$ | ∖ | ◯ | $\{{\u25ca}_{\mathbb{R}}^{i},\cdots \}$ | ∖ | |

⋯ | ⋯ | ⋯ | ⋯ | ⋯ | ⋯ | |

n | ${\mathtt{cid}}_{n}$ | ∖ | ◯ | $\{{\u25ca}_{\mathbb{R}}^{i},\cdots \}$ | ∖ |

Scheme | AKMB [42] | IBCPA [7] | EPCBV [43] | The Proposed Scheme |
---|---|---|---|---|

Anonymous Identity Updating | × | × | × | ◯ |

Unforgeability | ◯ | ◯ | ◯ | ◯ |

Collusion Attack Resilience | ◯ | × | ◯ | ◯ |

Sibiling Attack Resilience | ◯ | × | × | ◯ |

Session Key Establishment | ◯ | ◯ | ◯ | ◯ |

Conditional Privacy Preserving | ◯ | ◯ | ◯ | ◯ |

Scalability | × | × | ◯ | ◯ |

Key Escrow Resilience | ◯ | ◯ | ◯ | ◯ |

Replay Attack Resistance | × | ◯ | ◯ | ◯ |

Unlinkability | × | × | × | ◯ |

© 2020 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).