Vehicle-to-Everything (V2X) communication faces a critical authentication dilemma: traditional public-key schemes like ECDSA provide strong security but impose 2 ms verification delays unsuitable for collision avoidance, while symmetric approaches like TESLA achieve microsecond-level efficiency at the cost of 20-100 ms key disclosure latency. Neither meets 5G New Radio (NR)-V2X's stringent requirements for both immediate authentication and computational efficiency. This paper presents SALT-V, a novel hybrid authentication framework that reconciles this fundamental trade-off through intelligent protocol stratification. SALT-V employs ECDSA signatures for 10% of traffic (BOOT frames) to establish sender trust, then leverages this trust anchor to authenticate 90% of messages (DATA frames) using lightweight GMAC operations. The core innovation - an Ephemeral Session Tag (EST) whitelist mechanism - enables 95% of messages to achieve immediate verification without waiting for key disclosure, while Bloom filter integration provides O(1) revocation checking in 1 us. Comprehensive evaluation demonstrates that SALT-V achieves 0.035 ms average computation time (57x faster than pure ECDSA), 1 ms end-to-end latency, 41-byte overhead, and linear scalability to 2000 vehicles, making it the first practical solution to satisfy all safety-critical requirements for real-time V2X deployment.
翻译:车联网(V2X)通信面临关键的认证困境:传统公钥方案(如ECDSA)提供强安全性,但引入2毫秒验证延迟,不适用于碰撞避免;而对称方法(如TESLA)实现微秒级效率,却以20-100毫秒的密钥披露延迟为代价。两者均无法满足5G新空口(NR)-V2X对即时认证与计算效率的严苛要求。本文提出SALT-V,一种新颖的混合认证框架,通过智能协议分层调和这一根本性权衡。SALT-V对10%的流量(BOOT帧)采用ECDSA签名以建立发送方信任,随后利用该信任锚点,通过轻量级GMAC操作认证90%的消息(DATA帧)。其核心创新——临时会话标签(EST)白名单机制——使95%的消息无需等待密钥披露即可实现即时验证,而布隆过滤器集成以1微秒实现O(1)复杂度的撤销检查。综合评估表明,SALT-V平均计算时间达0.035毫秒(较纯ECDSA方案提升57倍),端到端延迟为1毫秒,开销为41字节,并可线性扩展至2000辆车,成为首个满足实时V2X部署所有安全关键需求的实用解决方案。