Skip to main content
Advertisement
Browse Subject Areas
?

Click through the PLOS taxonomy to find articles in your field.

For more information about PLOS Subject Areas, click here.

  • Loading metrics

Chaotic map based efficient anonymous authentication and key agreement scheme for VANETS

  • Dulam Devee SivaPrasad,

    Roles Writing – original draft, Writing – review & editing

    Affiliation Department of Networking and Security, School of Computer Science and Engineering, VIT-AP University, Beside AP Secretariat, Amaravati, Andhra Pradesh, India

  • Azees Maria

    Roles Conceptualization, Formal analysis

    azees.m@vitap.ac.in

    Affiliation Department of Networking and Security, School of Computer Science and Engineering, VIT-AP University, Beside AP Secretariat, Amaravati, Andhra Pradesh, India

Abstract

Vehicular Ad Hoc Networks (VANETs) have been developed as an important technology for improving road safety and traffic efficiency in intelligent transport systems. However, due to the increase in the number of cyberattacks, they have become vulnerable to several security threats that must be addressed. Although several works related to authentication and key agreement protocols have been proposed in the past, there is a significant overhead in both communication and computation. To overcome this burden, a Chebyshev chaotic map-driven anonymous authentication scheme with a key agreement scheme is proposed in this work. This work shows integrates a chaotic map with anonymous authentication, thereby balancing security and efficiency. The proposed scheme removes the bilinear pairing operations, thereby reducing the time required for cryptographic operations, which leads to a significant reduction in computation overhead. Moreover, Quantitative evaluation shows that the proposed scheme achieves a total execution time of only 0.9494ms representing a (49.7%−71%) reduction compared to existing schemes (1.8878-3.7756 ms) and a communication overhead of 264 bytes, which is (13.2%−57.4%) lower than most related works (84–620) bytes. Furthermore, the security analysis section addresses the secure nature of the proposed protocol in contrast to different types of security attacks. The efficiency of the proposed schema is validated against similar works based on the computation time of cryptographic operations using the Cygwin platform and is proven to be noteworthy.

1. Introduction

The Global Road Safety Report 2023, presented by the World Health Organization (WHO), disclosed that over 1.19 million lives are lost each year due to road traffic accidents [1]. According to the Ministry of Road Transport and Highways (MORTH) of India, road accidents have become a leading cause of death, particularly affecting individuals aged 5–29 years [1,2]. Recent studies highlight the urgent need for an intelligent or smart transport system to help reduce road accidents. In this regard, the development of Vehicular Ad-Hoc Networks (VANETs) has emerged as a promising solution for intelligent transport systems, enabling vehicles to communicate by exchanging messages. These messages give information about roadblocks, They tell about diversions and traffic updates. This real-time data helps other drivers drive better. VANETs have changed normal road systems into smart ones. They allow vehicles to talk to roadside units. Roadside units are called RSUs. An RSU works like a small cell network. It sends information to other vehicles or RSUs. When a vehicle shares information with an RSU it is called V2R communication. V2R stands for vehicle to roadside unit. When vehicles talk to each other it is called V2V communication. V2V stands for vehicle to vehicle.

VANETs have three main parts. First there are vehicles with onboard units. Onboard units are called OBUs. Second there are roadside units along the roads. Roadside units are called RSUs. Third there is a trusted authority. The trusted authority is the central manager for the whole VANET system. VANETs use dedicated short-range communication (DSRC). The DSRC is a type of wireless technology. It helps V2V and V2R communication work. Table 1 represents DSRC channel configuration table uses the 5.9 GHz frequency band. It lets V2V and V2R share information. This information helps manage traffic. It also helps send alerts for emergency vehicles. Shows these channels are split into two groups. The first group has one control channel called CCH. The CCH sends safety messages. These messages include bad weather conditions. They include traffic updates. They also include accident alerts. The second group has six channels called service channels (SCH). These service channels send non-safety messages. Examples are Internet access and infotainment apps.

Since VANET communication uses a public wireless network for V2V and V2R communications, it is essential to guarantee that all messages are properly communicated by authorized entities and that the integrity of the communicated messages is preserved and not lost during transmission. Therefore, a strong authentication protocol is crucial for VANETs to avoid serious security attacks and threats to the network. If a proper authentication mechanism is not implemented in VANETs, malicious entities may send bogus messages, such as false congestion reports and location information, which can lead to traffic flow manipulation. In VANETs, vehicle users exchange information about their locations and speeds with other vehicles. Without proper privacy preservation, attackers can track the location of vehicle users and their real identities, leading to the misuse of personal information. Therefore, it is necessary to protect the privacy of vehicle drivers from location tracking, identity profiling and eavesdropping. However, implementing a strong privacy-preserving mechanism can increase the computational cost and communication delay, thereby affecting the performance of VANETs in real time environments.

Hence, it is essential to prepare lightweight privacy-preserving mechanisms to maintain the communication cost and communication delay as low as possible. Where most existing works rely on heavy cryptographic computations such as elliptic curve cryptography (ECC) and Rivest–Shamir–Adleman (RSA), leading to higher computational latency and communication overhead. In connection to this, in this paper, a novel anonymous authentication schema is proposed with the support of Chebyshev polynomial. If these security measures are not addressed properly, it may lead to situations in which an unauthorized entity may send fake messages, such as fabricated traffic updates, which mislead the driving conditions of other drivers. If authorization is not addressed properly, an attacker can easily enter the VANET system and perform all illegal activities. Therefore, if VANETs do not follow strong security practices, they may be attacked by spoofing, message tampering and denial-of-service attacks. These attacks compromise the safety of VANET networks. This authorization plays an important role in VANETs; therefore, every genuine participating entity (vehicle, RSU and TA) in a VANET should follow a proper procedure. This procedure will ensure that only authorized participants share the information, stop impersonation of trusted sources and stop spreading fake messages by unauthorized parties. Maintaining the anonymity of participants in a VANET is as important as protecting their privacy. These preserve vehicles and other participating entities from disclosing their real identities and locations during communication. This anonymity will stop the tracking and profiling of vehicles and, finally, privacy breaches from occurring. If a privacy breach occurs, personal information, such as the original identity proof and current vehicle location, can be disclosed to the attacker. The authentication (one-way identity verification), mutual authentication (two-way verification) and key agreement (shared secret establishment). Therefore, security, authorization and anonymity are important concerns that must be addressed to maintain secure and privacy-preserving communications in VANETs.

Recently, the application of Chebyshev polynomials in cryptography has gained attention. Their use in key management for VANETs is particularly noteworthy. The unique mathematical properties of Chebyshev polynomials make them well-suited for this purpose. Properties such as the semigroup property and recurrence relations ensure the security of VANETs. While ECC performs well in static or semi-dynamic environments, its frequent re-authentication in VANETs is clumsier than evaluating Chebyshev polynomials, leading to delays. Similarly, lattice-based methods, with their significantly larger keys and messages compared to Chebyshev-based methods, result in high bandwidth and verification overhead. Since VANETs are highly sensitive to latency, the bulky operations of lattice methods are practically challenging for fast moving vehicles. In comparison to ECC and lattice approaches, Chebyshev polynomials offer the lightest, fastest and most practical solution. In VANETs, Chebyshev polynomials are employed to generate keys. The key agreement policy is crucial in VANET networks, providing authorizations for vehicles, RSUs and the TAs. For this purpose, the semigroup property of Chebyshev polynomials is utilized to generate public and secret keys for encryption and authorization. The security provided by the Chebyshev Polynomial Discrete Logarithm Problem (CPDLP) is considered sufficiently strong for various cryptographic operations because it can generate one-way functions in connection with chaotic maps. This combination strengthens the security. Chaotic maps can provide Pseudo-Random numbers. Randomness is an important factor for security in cryptography. Chaotic maps are unpredictable because even smaller changes in the initial values result in completely unpredictable results.

The primary contributions of this work are summarized as follows, addressing the conflicts and challenges:

  • To propose a novel TA-based anonymous authentication protocol to secure the user’s identity while communicating with others.
  • To propose a session key distribution protocol to preserve the confidentiality of the future communicating messages.

Roadmap: The remainder of this paper is organized as follows. Section 2 surveys the related work, highlighting the contributions and limitations of existing approaches. Section 3 outlines the preliminaries, including the system model, proofs of the semigroup basic property of Chebyshev polynomials, attack model and notation. Section 4 details the proposed model, followed by an extensive security analysis presented in Section 5. Section 6 presents the performance evaluation of the proposed scheme, its limitations. Section 7 elaborates on the analysis conducted via NS-3 simulations. Section 8 discusses the limitations of the current work and outlines directions for future research. Finally, Section 9 concludes the paper.

2. Related work

To provide appropriate security and privacy in VANETs, most research has focused primarily on developing methods for anonymous authentication and effective key management. Table 2 summarizes the existing authentication and key agreement schemes for VANETs. The table compares protocols based on key parameters such as cryptographic technique used, security features achieved (e.g., mutual authentication, privacy preservation, key agreement), computational and communication overhead. It also mentions the limitations. This survey highlights the research gaps that motivate our proposed scheme.

To achieve guaranteed conditional privacy, Zang et al. [3] introduced PA-CRT, an authentication framework for VANET network based on the Chinese remainder theorem (CRT). It minimizes computational costs by using lightweight modulo operations and fingerprints for authentication, instead of long-term secret storage. This scheme provides traceability, anonymity and safeguards against replay and impersonation attacks on the user. To provide strong privacy and secure communication in IoVs, Vasudev et al. [4] introduced the P2-SHARP protocol, which mainly focuses on transmitting warning messages. To achieve resistance against replay, man-in-the-middle (MITM) and trusted platform device (TPD)-stolen attacks, the protocol is equipped with lightweight hash-based authentication.

Similarly, Wang et al. [5] suggested that there is a growing need for private and secure communication in VANETs. To address these challenges, he proposed the Improved security certificates conditional privacy preserving authentication (ISC-CPPA) method, which addresses challenges such as dynamic key updates, random tag encryption and certificate-less cryptography to improve privacy, traceability and performance. Previous methods, such as public key infrastructure (PKI) and IDC-based CPPA, encountered difficulties with escrow and key management (Li et al.). Despite efforts to increase security, Li et al.’s CL-CPPA method does not provide complete anonymity. Shim, Azees and Shen later proposed substitutes; however, they encountered challenges with attack resistance and revocation efficiency. Zhou et al. [6] proposed blockchain based smart contracts system for vehicular networks but failed to address regular scalability challenge of blockchain when it comes to practicality.

Privacy preservation maintains communication go smooth and secure in VANETs. The old traditional methods like PKI and digital signatures have problems. Sometimes it leads to single point failure. Sang et al. [7] created a lightweight secure model PACM (Phase Amplitude Coupling index). The PACM majorly uses ECC and XOR operations. It provides lightweight mutual authentication. By the help of bloom filters in PACM fast certificate verification can be performed. Cheng et al. [8] proposed the anonymous authentication and privacy preserving reliability evaluation (AARE) protocol. This protocol uses homomorphic encryption and mainly used for dense networks. These approaches increase the user privacy and confidentiality management. These cannot survive quantum attacks. Cheng et al. [9] introduced a new schema which is lightweight and quantum random number based. It uses zero knowledge proofs. This scheme guarantees strong security because of quantum random numbers. It also ensures scalability and low overhead.

Yang et al. [10] proposed Certificateless Aggregate Signature schemes (CLAS). They reduce overhead. They also remove key escrow issues. This work introduces a method that does not rely on pairing, a provably secure CLAS protocol featuring a new aggregation algorithm that supports public verification and highlights conditional privacy with traceability. Maintaining message integrity and privacy in VANETs is challenging because they are compromised by outdated or interdependent cryptographic keys. Therefore, due to this reason Baee et al. [11] described the importance of long-term key update mechanisms and the security risks generated through interdependent key structures. This work highlights the issues demanding a secure and efficient key update protocol, introducing FLKUP and FSKUP for long- and short-term key updates to ensure perfect, forward secrecy and unlinkability.

Lam et al. [12] highlights involvement of trust in VANETs is important. Few models use Bayesian theory, Some use Dempster-Shafer theory or DST. To handle ambiguity in better way. This work introduces trust management framework MEFPB. It handles different types of date i) direct data and ii) indirect data. MEFPB also boosts trust accuracy. It resists on-off attacks and black hole attacks and it resists path manipulation threats. It does this with a path-backtracking technique. Tan et al. [13] proposed an attribute-based authenticated key management system. It uses certificateless cryptography. It also addresses batch authentication. The system supports V2V anonymous and accountable communication.

The Lin et al. [14] But these methods are usually expensive. They may also need special trusted hardware. Some current blockchain systems like CertCoin and BPAS are slow. They are not very good at tracking. EBCPA solves these problems. It uses smart contracts, digital signatures and key generation methods. Liang et al. [15] proposed a Certificateless Aggregate Signature (CLAS). This method helps for safe vehicle communications. It uses certificates for this. This work finds a important problem in Mei’s work. Then it comes up with a better CLAS model. This new model is stronger. Which is capable to protect against Type I and Type II attacks. Bojjagani et al. [16] described a lightweight security protocol. It is called AKAP-IoV. It uses Elliptic Curve Cryptography or ECC. The protocol uses secure session key generation to support mutual authentication. Mansour et al. [17] proposed the ALMS protocol. This protocol addresses challenges such as multicast communication in dynamic vehicular environments. Existing solutions use asymmetric and symmetric key protocols with high computational costs. The ALMS protocol includes the Chinese remainder theorem (CRT), prime factorization and discrete algorithms to achieve efficient, scalable and secure key distribution with minimized overhead. Madani et al. [18] proposed Chebyshev polynomials algorithm designed to resist side channel attack with high-speed cryptographic operations with low resource used. However, the complexity of the side-channel countermeasure implementations may increase.

Singh et al. [19] described a framework that combines blockchain decentralization with Chebyshev polynomial cryptography for security and trust; however, this protocol suffers from challenges such as blockchain consensus mechanisms and scalability challenges. Zang et al. [20] proposed energy-efficient authentication and key agreements for smart grid environments with Chebyshev chaotic map’s cryptographic properties for secure key agreement. However, they failed to discuss the practical implementation challenges. Mohamed et al. [21] proposed a simple and efficient batch authentication scheme that can verify many electrical vehicles for Vehicle-to-Grid (V2G) networks at a time. It uses bilinear pairings and aggregate signatures to verify multiple electric vehicle (EV) signatures simultaneously, which helps save both time and computing resources. The schema also combines certificateless cryptography with blockchain to keep records secure and decentralized. While protecting user privacy through features like traceability and controlled identity sharing when required. The system works well in terms of speed, scalability and low cost when compared to traditional methods. But the schema leaves as it is does not look much into things like how blockchain affects storage for long periods and power utilizations. Wang et al. [22] proposed two procedures. i) CDAS (Centralized Data Authentication Scheme) tailored for centralized networks and improves encryption and signature verification and ii) DDAS (Distributed Data Authentication Scheme) targets distributed setups using a matrix structure to avoid system crashes and reduce communication overhead. Both methods showed better speed, security and efficiency than other approaches along with the privacy. However, this work fails to detail the implementation in real-world deployment. Vangujar et al. [23] developed a lightweight blockchain-based key management for V2G with batch processing by using aggregated signatures. This accommodates large groups of EVs to get authenticated and managed together, that results in reduced delays and communication needs. It maintains privacy and forward secrecy and uses smart contracts for key updates and revocations. Krishnan et al. [24] proposed a secure handover authentication scheme for 5G vehicular networks using SDN and MEC to reduce delay and overhead. However, this scheme uses a Handover Key (HK) for fast reauthentication without disturbing the base network. They proposed their future work with AI-based handover optimization and blockchain to achieve more security.

Current authentication and key agreement methods for VANETs have serious problems. These problems make them hard to use safely and efficiently. Real time scenarios change regularly. Majority methods depend on a CA or RSUs. But these can fail easily. These schemes influence to important attacks like Sybil or insider threats Our proposed scheme fills this gap. It uses chaotic maps as a fast and secure alternative. It provides anonymous authentication. It provides efficient key agreement. It gives better privacy. With low lower overhead. It also reduces dependence on CA.

3. Preliminaries

3.1 System model

The system working architecture of the proposed schema is depicted in Fig 1. This architecture depicts real-time data transmission between vehicles, RSUs and TA. The main entities of the architecture are the TA, RSU and vehicle users.

Trust Authority (TA): It acts as a centralized unit for the entire network. The major responsibilities of the TA include vehicle registration, RSU registration and secure credential distribution to the RSU and vehicles. The trusted authority is responsible for the registration of RSUs and vehicle users in the VANET system. During the registration period, the TA obtains the required credentials from the vehicle users and RSUs. Once the registration is completed, the TA issues some secret and public parameters to the vehicles and RSUs to make them authenticated entities of the VANET system. These issued parameters must be used by RSUs and vehicle users. Every geographic zone is assigned with a TA. However, the TAs of all geographic zones are interconnected with each other through fibre optic cables. Therefore, registration in any one TA is sufficient to prove its authenticity in the VANET system for vehicles or RSUs. Moreover, it is assumed that the TA has a strong firewall and intrusion detection system (IDS) to ensure that the TA is completely unbreakable because of security attacks.

Vehicles: In VANETs, vehicles serve as mobile nodes for data transmission and reception, integrated with On-Board Units (OBUs) that collect and validate traffic-related sensitive data, including position, velocity and traffic status. These vehicles share the information with other nearby vehicles as well as with the RSUs. Additionally, other units in the network provide useful services to vehicles, such as real-time updates and safety alerts. In general, inter-vehicle communication occurs every 100–300 milliseconds, enabling the rapid exchange of critical traffic data. This improves situational awareness and supports efficient decision-making in vehicles.

Roadside Units (RSUs): These are deployed at roadside locations, RSUs serve as important interfaces between vehicles and other RSUs. RSUs gather and process data from authorized vehicles. After processing, they extract useful information from the data and transmit it to the TA and other vehicles. The TA stored this refined information for future reference. In later implementations, RSUs could be equipped with larger storage capacities; thus, due to this reason RSU can act as fog nodes for data storage to perform real-time information updates in large-scale networks.

3.2. Chebyshev polynomial

This section describes the fundamental characteristics of the Chebyshev polynomials and their computational challenges.

Definition 1 (Chebyshev Polynomial Chaotic Map): For any integers n and , the Chebyshev polynomial can be defined as either a trigonometric form which is the called cosine function (1) or recursive form which is represented in (2). In these the chaotic behaviour can be experienced in recursive form when [25,26].

(1)(2)

Definition 2 (Semigroup Property): The semigroup property of the Chebyshev polynomial is defined by (3).

(3)

The Chebyshev polynomial semigroup property remains valid even when its domain is extended to the interval . The improved Chebyshev polynomial is defined in (4), where p represents a large prime number:

(4)

The Chebyshev polynomial possesses numerous significant properties; however, the semigroup property is particularly used in our proposed work. Table 3 represents Chebyshev polynomials for degrees n = 1–11. These polynomials satisfy the recurrence relation with initial values and . For cryptographic applications, the domain is extended to and computations are performed modulo a large prime p, as shown in Equation (4). The chaotic nature of Chebyshev polynomials emerges for . Table 3 represents the Chebyshev polynomials of order up to n = 11.

thumbnail
Table 3. Chebyshev polynomials of different orders (n).

https://doi.org/10.1371/journal.pone.0357045.t003

3.3. Proof of semigroup property

The proof of the semigroup property is described as follows by considering the values u = 2 and v = 3 from equation (3)

(5)(6)(7)(8)(9)(10)

3.4. Computational Hardness Assumptions

The security of the proposed scheme relies on the fact that certain mathematical problems related to extended Chebyshev polynomials over a finite field are very hard to solve.

Definition 3 (Chebyshev Chaotic Map-based Discrete Logarithm Problem (CMDLP)): Suppose we are given two values x and y, where:

(11)

It is computationally very difficult for any probabilistic polynomial attacker (PPT) to find the value of r. In simple terms, if the attacker is successful in finding the values of x and , it is hard to determine r. For large prime numbers p and , the probability that any PPT adversary A can find r is extremely small.

(12)

where is a negligible function. Equation (11) specifies that the probability of any probabilistic polynomial time adversary A successfully finding the secret integer r is less than a negligible function [26].

Definition 4 (Chebyshev Chaotic Map-based Diffie-Hellman Problem (CMCDHP)): Now suppose we are given three values x, , [25]. It is computationally very hard for a PPT attacker to compute equation (12) without knowing the values of r and s.

(13)

In simple terms, even if the intruder manages to have x, and values, they still cannot compute the shared value [2527].

Formally, equation (13) specifies that the probability of any probabilistic polynomial time adversary A successfully finding the secret integer r is less than a negligible function .

(14)

3.5. Attack Model

In VANETs, the open and constantly changing communication environment presents special security challenges that make them vulnerable to various types of attacks. This work considers an adversary operating under the Dolev–Yao model [28], in which the attacker has full control over the communication channel. The adversary can intercept, modify, replay and inject messages into a network. The adversary has limited computing power. They cannot break secure cryptographic methods. These methods include encryption or signatures. Breaking them requires special keys. The attacker does not have those keys.

3.5.1. Adversarial capabilities.

  • Network Control: The adversary can fully control the communication channel. They can intercept messages. They can modify and inject new manipulated messages. They can resend the old messages. They can delete messages too.
  • Knowledge: The adversary can know all protocols and algorithms. But they have no access to private cryptographic keys.
  • Computation: The adversary is limited by standard computational hardness assumptions. So, they cannot break encryption and digital signatures.

3.5.2. Attack scenarios.

The adversary may attempt the following attacks relevant to vehicular networks.

  • Bogus Information Attack: The adversary attempts to inject false data for example fake traffic alerts to mislead vehicles and RSUs.
  • Impersonation Attack: The adversary attempts to masquerade as a legitimate vehicle or RSU by spoofing valid identities.
  • RSU Replication Attack: The adversary installs a rogue RSU or replicates a legitimate RSU identity to intercept or manipulate communication.
  • Denial-of-Service (DoS) Attack: The adversary floods the channel with excessive malicious traffic to degrade service availability.

The possible attacks presented in Table 4 may occur on the VANET infrastructure. Therefore, due to this reason strong security features such as efficient authentication protocols, message integrity checks, encryption and privacy-preserving techniques are seriously suggested.

3.6. Notations

Table 5 represents the list of notations and abbreviations to enhance the readability of the proposed work throughout all the sections.

4. Proposed work

Initially, the TA chooses a random integer x generated within the range , where p is a large prime number. Further, the TA chooses a random number as private key. Furthermore, the TA computes its public key as . Finally, the TA publishes further as public parameters. Here, is the one-way secure hash function (SHA-256), which computes hashes of critical protocol data, guaranteeing both data integrity and one-way irreversibility. By combining the dynamically generated seed with hashing, our system provides robust protection against message tampering and unauthorized access while maintaining computational efficiency.

4.1. Vehicle registration ()

In our protocol, a vehicle user () must directly visit the TA for the initial registration process. At the time of the initial registration process, the TA collects all the necessary details and documents from and verifies them with the support of any government-based organizations. After document verification is completed, the TA first assigns a real identity for . Moreover, the TA computes the public key of as , where is the private key for . To preserve the privacy of , the TA also computes a dummy identity for as . Here, the mapping of the dummy identity to the real identity is performed only at the TA. Moreover, the TA stores in its database for future reference. At the end of the vehicle registration process, the TA returns to in a secure manner.

4.2. RSU registration ()

Similar to the vehicle registration process, each is required to register with the TA before its deployment on the roadside locations. In connection to this, the TA first assigns a real identity for . Then the TA computes the public key for as . Here, is the private key of . Moreover, to preserve the privacy of , the TA generates a dummy identity . Finally, the TA provides to in a secure manner for future communications. Besides, the TA maintains these parameters in its database.

Fig 2 represents the flowchart of the anonymous authentication mechanism in proposed scheme between , and TA.

  • The authentication process is initiated by the user , by sending I1 to the RSU where I1 consists of all the relevant parameters of .
  • The then computes I2 and sends it to TA. The parameter I2 includes details of I1 too.
  • The TA accepts I2 only if it passes the freshness test of timestamp , if I2 fails to pass this test, the protocol will be terminated.
  • If I2 is fresh, the TA validates the by checking whether or not. If this condition is satisfied, the TA authorizes the RSU; otherwise, the protocol is terminated.
  • Once the TA authorizes RSU, it will authenticate the user by checking parameter I1, if the condition is satisfied the TA approves the user’s authentication, otherwise the protocol will be terminated.
  • The TA generates session keys to perform secure communications between the RSU and user in the future.

The detailed explanation and execution of the anonymous authentication process are described in the following sections.

Step 1: To prove the anonymity to other entities in the network, must perform the following anonymous authentication process. In connection to this, first computes in such a way that

(15)

where,

(16)

where:

  • is the dummy identity of the vehicle,
  • is the current timestamp to ensure message freshness,
  • is the chaotic-map-based shared value derived from the vehicle private key and the TA public parameter b,
  • represents the current timestamp.

Then, sends

(17)

Step 2: By receiving I1 from , the computes in such a way that

(18)

where,

(19)

then sends equation (19) to TA

(20)

where:

  • is the RSU’s dummy identity,
  • is the RSU’s current timestamp and
  • is the RSU’s ephemeral chaotic value generated using its random nonce ,
  • represents the current timestamp.

Step 3: By receiving I2, the TA first checks whether . If this condition is satisfied, then I2 will be accepted, otherwise, it will be rejected. Once the timestamp verification is successfully completed, the TA computes

(21)

where , is the TA-computed verification value corresponding to the RSU’s nonce-based chaotic calculation.

Then, the TA checks whether , if it is correct, then the TA extracts I1 from I2 and checks the authenticity of by ensuring

(22)

where , is the TA’s verification value for the vehicle’s chaotic-map authentication. If , the vehicle is authenticated.

Step 4: TA computes the following parameters

The TA computes two masking values:

(23)(24)

where:

  • and are public keys of RSU and vehicle respectively,
  • and are their private random secrets.
(25)(26)

Where m,n are random nonces chosen by TA.

Session Key:

(27)(28)(29)

Finally, TA sends equation (29) to

(30)

Then calculates E1 by using its own parameters along with , which is received from I7, to retrieve . After that, retrieves from I5 using . Then, sends to . Upon receiving it, computes E2, retrieves from I4 and extracts from I6.

Step 5: By receiving I7 from TA, extracts from I3 as follows

(31)

Here, E1 can be calculated by using the parameters , , . After that, computes the session key from I5 in such a way that

(32)

Then the sends to .

Step 6: By receiving , extracts from I4 by performing

(33)

Here E2 is calculated with the support of his private key . After that, computes the session key from I6 in such way that

(34)

Both parties now share the same session key .

Step 7: During message transmission, vehicles and RSUs attach their dummy identities along with the messages. In the case of any misbehaviour, the TA can trace the vehicle or RSU using these dummy identities. After identifying the real identities , the misbehaving vehicle or RSU is revoked from the VANET system and both their real and associated identities are added to the revocation list maintained by the TA. Before participating in communication, each vehicle or RSU must check the revocation list. Fig 3 illustrates the conditional privacy preserving revocation and identity tracing that when an identity appears on the list, the corresponding RSU or vehicle is denied permission to join the network.

thumbnail
Fig 3. Revocation and identity tracing flowchart.

https://doi.org/10.1371/journal.pone.0357045.g003

After obtaining , is used to make confidential communication with by the user. Here, is used as a symmetric key for a session established between the and . Here, to preserve the confidentiality of message m, advanced symmetric key based encryption algorithms are used in this paper in support of as

Secure message transmission uses symmetric encryption:

(35)

and is decrypted by :

(36)

5. Security analysis

The following section explains how the proposed scheme addresses various security attacks through formal and informal analyses.

5.1. Formal security analysis

Formal security analysis based on the ROR model is explained in this section. The proposed Chebyshev polynomial based anonymous authentication protocol is analysed based on the ROR model [29]. The adversary A interacts with parties via Send, Execute, Reveal, Corrupt and a single Test query to a fresh session. Let be the challenger’s hidden bit. Upon Test, the challenger returns the real session key if b = 0 and a random key of the same length if b = 1. The adversary outputs a guess . The advantage of A in this experiment is

(37)

Thus denotes the distinguishing advantage between a real session key and a random string.

5.1.1. System Parameters.

  • : number of hash queries (modelled as RO of size ).
  • : bound on Send (active forgeries)/concurrent sessions relevant to a particular partner.
  • L: session-key length (bits) output by the KDF.
  • |D|: domain size of protocol nonces/challenges (timestamps/nonces/labels) needed to bind a forged message to a specific fresh session.
  • Long-term secrets: vehicles , RSU . Session key depends on (i) Chebyshev-derived values and (ii) fresh nonces/challenges.
  • Freshness: The Test session and its partner have not been revealed; neither both long-term keys nor their session secrets are simultaneously exposed before Test.

5.1.2. Game sequence and lemmas.

The games are used in this work and Succ(G) is used for the event where “A guesses b correctly in game G.” The bounding of will follow from a telescoping argument over these games.

Game : Real Protocol Lemma 1.

(38)

Explanation.

Game : Passive Eavesdropping only All executions are honest: A only observes , .

Lemma 2 (No passive gain):

(39)

As a result, without and , the key cannot be derived and there is no Test-distribution change.

Game : Active Send/Hash Forgeries A crafts forgery. Authentication binds to RO outputs on transcripts containing .

Lemma 3 (Birthday bound):

(40)

As a result, any successful impersonation that changes distributions must induce a RO collision on some transcript component and apply birthday bound.

Game : Corrupt (Key Exposure) A may corrupt either a vehicle or an RSU (but freshness forbids corrupting both partners before Test).

Lemma 4 (Single-party exposure is insufficient):

(41)

As a result, with at most one long-term key being exposed, deriving still requires (a) binding to the correct fresh transcript (guessing a nonce/challenge with probability per attempt) and (b) predicting the L-bit KDF output (probability ). Over relevant attempts, union bound gives .

Game : Reduction to Chebyshev Hardness If A can still distinguish, a solver B is built for the Chebyshev problem (i.e., recovering or without b or ) by embedding the challenge into a RO query/transcript.

Lemma 5 (Reduction):

(42)

Standard RO-programming: B guesses the decisive RO query (probability ) and answers using its Chebyshev challenge; success of A yields a solver for the hard problem.

Game : Final Guessing All avenues closed; only random guessing remains.

Lemma 6.

(43)

As a result, by construction, test key is independent random.

5.1.3. Theorem: ROR Security of the proposed scheme.

Theorem 1. For any PPT adversary A, its advantage is bounded as

(44)

Proof: Triangle inequality is applied over hybrids:

(45)

Bound each term by Lemmas 2–5; Lemma 6 gives the terminal .

5.1.4. Corollary: Adaptive indistinguishability with single-party corruption.

Let A be adaptive (may interleave Send/Execute/Reveal/Corrupt before/after session completion) and assume freshness (never both partners corrupted before Test and no Reveal of the Test session). Then the session key of the Test session is indistinguishable from random:

(46)

The adaptive setting does not change the Lemmas 3–5 under the freshness condition, and the single-party leakage is absorbed by Lemma 4’s term.

This expanded real-or-random (ROR) security model directly integrates the structure, keys and parameters of our proposed Chebyshev polynomial-based anonymous authentication protocol. Each security game matches one specific attack. The attack targets a step or a part of our scheme. This shows our scheme is strong. It can resist many types of attacks.

5.2. Formal security verification using scyther

The formal security analysis is essential for credibility. Accordingly, we have supplemented our informal security analysis with formal verification using the Scyther tool shown in Fig 4.

thumbnail
Fig 4. Formal security verification of the proposed work using Scyther.

https://doi.org/10.1371/journal.pone.0357045.g004

The results from the Scyther tool revealed the following observations:

  • All secrecy claims (Secret IV, Secret k (vehicle, A), Secret n, Secret k (TA, RSU), Secret s1, Secret s2) were verified as OK-no attacks found.

Description: All secrecy claims being “OK” means that under the Dolev-Yao attacker model (where the adversary controls the network), none of the secret values (temporary identifiers, shared keys, nonces, or master secrets) can be learned by the adversary. This formally proves the “confidentiality” and “privacy” of our protocol.

  • All liveness and synchronization claims (Niagree, Nisynch, Alive) for vehicles, RSUs and TAs were verified as ok-no attacks within bounds.

Description: All liveness and synchronization claims being “OK” means the protocol formally proves: (1) Mutual authentication is achieved between all parties (Vehicle RSU, RSU TA); (2) Replay attacks are impossible because nonce synchronization prevents message reuse; and (3) Protocol liveness is guaranteed because honest participants always complete the protocol successfully.

  • The verification confirms that our protocol guarantees mutual authentication, session key secrecy and resistance to replay attacks under the Dolev-Yao attacker model.

Regarding public availability of Scyther code: While we fully support open science and reproducible research, the complete protocol specification contains proprietary implementation details that are currently part of a pending patent application / confidential institutional review. Therefore, we are unable to publicly release the full Scyther input files currently.

5.3. Informal security analysis

The Vehicle users and RSU signatures are important in this method because they help protect against security attacks. This method ensures that an outsider cannot create a valid user signature. The next section explains how this method protects against various attacks.

5.3.1. Impersonation attack.

The proposed method withstands impersonation attacks. To execute an impersonation attack, the attacker should pretend to be a user in the proposed work. However, is unable to impersonate as due to the registration process in the TA. To impersonate as , has to first generate the value . To generate the values and A are required. However, is not possible for to be regenerated. To regenerate , needs b. However, it is impossible for an adversary to get b from the . Since Chebyshev maps operate over finite fields, reversing is very difficult and it is impossible for an adversary to calculate .

5.3.2. Replay attack.

The proposed method counters replay attacks. In the proposed work, user sends to . Once this message is received by , it ensures the freshness of the timestamp in such way that . If this condition fails, the message I1 is simply rejected by the . In this condition, represents the time at which I1 is received by and represents the threshold value for time limit. Similarly, the TA also checks the timestamp for I2 by checking . In our proposed work, the timestamp is attached to all the computational messages in such a way that our scheme can efficiently survive replay attacks.

5.3.3. Message modification attack.

The proposed scheme is robust against message modification attacks. In our proposed scheme, is calculated as where . To modify , the attacker has to know the value of from A. It is impossible due to the hardness of Chebyshev maps over finite field. Moreover, after sharing the session key successfully, the message is encrypted using advanced symmetric encryption techniques. For instance, in the proposed work the message is encrypted using the session key

(47)

In this case, changing the message content M by breaking the symmetric encryption, such as 3-DES, within a polynomial time is highly impossible. Hence, our proposed scheme withstands message modification attacks.

5.3.4. Privacy preservation.

The proposed scheme preserves the privacy of the user and RSU while communicating over the network. It is important to maintain the privacy of the user from attackers to prevent identity leakage. In connection to this, the proposed work includes dummy identities of the user and RSU during their communication in the channel. In the proposed work, transmits to and includes to . That is, instead of sharing the real identity, includes a dummy identity in such a way that the attacker cannot take any personal information about . In the case of any dispute, the of is mapped to the real identity of by the TA. Moreover, in the case of misbehaviour, the user is no longer authorized to access the system and their real identity is revealed to prevent further damage to the system. Similarly, the uses its dummy identity with others to preserve the system from identity-based attacks.

5.3.5 Man-in-the-middle (MITM).

The proposed work withstands man-in-the-middle (MITM) attacks by ensuring that all communication between the user , and the TA is protected using Chebyshev polynomial computations and timestamp-based freshness verification. In our scheme, the key value is an important component used to compute . For an attacker to successfully perform an MITM attack, they must regenerate or the session key. However, since A is based on the private key and secure parameters from TA (like b) and due to the hardness of reversing the Chebyshev map over a finite field, it is computationally impossible for to forge a valid A. Moreover, messages are secured using a symmetric encryption scheme with the session key and timestamps are validated to ensure freshness. Any tampering or delay introduced by would be immediately detected and rejected by the system. Hence, the proposed scheme strongly resists MITM attacks.

5.4. Analysis against advanced threat models

Advanced threat models are essential for demonstrating the strength of any security protocol. The security analysis has been extended to explicitly address sophisticated threats and to clarify how the scheme is designed to mitigate insider threats and Sybil attacks.

5.4.1. Strength against insider threats.

An insider threat involves an authorized, registered entity (e.g., a vehicle or RSU) turning malicious.

Threat Scenario: A registered vehicle , with its valid credentials , starts behaving maliciously (e.g., sending false safety messages, attempting to track other vehicles).

  • Traceability: The Trusted Authority (TA) can cryptographically trace the malicious activity back to the vehicle’s real identity . This is possible because the TA knows its master key b and can reverse the Dynamic ID operation: (48)
  • Revocation: Once identified, the TA can immediately revoke the vehicle by adding its public key to the Certificate Revocation List (CRL). This CRL is distributed to all RSUs.
  • Access Denial: When an RSU receives an authentication attempt from , it first checks the CRL. The RSU then denies access right away. It does not perform any cryptographic verification first. This makes the insider’s credentials useless.

Our system does not prevent an insider from becoming malicious but provides a rapid and effective mechanism to detect, trace and dismiss them from the network. This attempt can neutralize the threat.

5.4.2. Strength against sybil attacks.

A Sybil attack works like this. One bad actor creates many fake identities. The goal is to overload the system or to gain too much influence.

Threat Scenario: An attacker attempts to register multiple vehicles with fake identities. The attacker wants to create a fake traffic jam or neutralize the authentication process.

  • Preregistration with TA: Our protocol requires every vehicle to be uniquely registered with the central TA with government-issued ID proofs. This registration happens before the vehicle joins the network. This process is mandatory.
  • Identity Binding: During registration, a real identity is cryptographically linked to a specific public key . The public key comes from the vehicle’s private key. The real identity is also linked to a trusted authority.
  • Cost of Identity: Getting a valid identity has a high cost. The attacker must go through formal registration for each identity. So, the Sybil attack is stopped. An attacker cannot arbitrarily generate an infinite number of valid tuples.

The central preregistration requirement blocks Sybil attacks. Our scheme guarantees that each authenticated identity corresponds to a single registered entity only.

6. Performance analysis

This section describes computational costs. It compares the proposed scheme with other existing schemes. The overall cost is measured by execution time; this time covers the authentication phase and verification phase for the User and the RSU.

6.1. Real-time feasibility assessment

To evaluate the practical applicability of the proposed VANET authentication scheme, the computational cost and communication overhead must satisfy the stringent latency requirements of real-time vehicular environments. For this purpose, the execution time of each cryptographic operation is evaluated individually to accurately estimate the overall computational cost of the authentication protocol. Table 6 presents the computational time required for various cryptographic operations, which serves as the basis for the subsequent computational cost analysis.

thumbnail
Table 6. Computational time for various Cryptographic operations.

https://doi.org/10.1371/journal.pone.0357045.t006

The measured operations include hash functions, Chebyshev polynomial evaluations, bilinear pairings, XOR, and modular operations. The protocol was implemented on a laptop with the following configuration: AMD Ryzen 5 7520U processor, Radeon graphics, 2.80 GHz CPU, 8GB RAM and Windows 11 Home operating system.

According to the proposed model, to perform the anonymous authentication process, the user and the together require two Chebyshev polynomial operations , two hash function operations and one keyed hash function using chaotic map. Similarly, for verification, the Trusted Authority (TA) needs two Chebyshev polynomial operations , two hash function operations and one keyed hash function using chaotic map. However, because these operations contribute a minimal computational cost, they were not considered in this performance analysis. The proposed protocol has been compared with other similar schemes to evaluate efficiency.

6.2. Computational cost

The computational efficiency of the proposed scheme was demonstrated in Table 7 that shows comparison with other existing schemes [3033]. The proposed scheme considers two hashing operations and two Chebyshev polynomial computations at both the message generation and verification stages, resulting in ms for each step and a total execution time of ms, which is significantly lower than all compared schemes [3033] Specifically, when Compared to the existing schemes, the proposed work reduces the total computational cost by a minimum of 49.7% (against Yang et al. [30]) and a maximum of 74.9% (against Al-Shareeda et al. [33]). representing a substantial computational advantage. This improvement is attributed to the elimination of bilinear pairing operations and the use of efficient Chebyshev polynomial evaluations.

thumbnail
Table 7. Comparison of Computational cost with various schemes.

https://doi.org/10.1371/journal.pone.0357045.t007

In comparison, Tomar et al. [32] has the highest computational cost, with a total execution time of ms, due to the major reliability on multiple Chebyshev polynomial operations () and hash function operations () across both message generation and verification phases. Jie Cui et al. [31] follows with a moderate total cost of ms, primarily attributed to extensive point multiplication on ECC combined with Chebyshev polynomial operations (), which introduce significant modular exponentiation delays. Jiyun Yang et al. [30] shows a relatively lower total execution time of ms among the existing schemes, yet it still requires twice the number of Chebyshev polynomial operations compared to the proposed work. Whereas Shareeda et al. [33] evaluate the complete authentication process based on the execution time of cryptographic operations performed by the vehicle, Fog server, and Trusted Authority (TA). Specifically, the authentication phase comprises two hash function operations, four Chebyshev polynomial operations, and one chaotic map based keyed hash. The verification phase, in turn, incurs separate computational costs for the vehicle, Fog server, and TA, resulting in a total execution time that is approximately three times that of the authentication phase alone. shows the second highest computational cost of ms due to extensive Chebyshev polynomial operations, hash operations, modular operations and multiple rotation functions. As shown in Fig 5, the bar graph represents total execution time (ms) for the proposed scheme with other existing schemes.

thumbnail
Fig 5. Comparison of computational cost (ms) for 1 to 100 vehicles with other schemes.

https://doi.org/10.1371/journal.pone.0357045.g005

In contrast, the proposed scheme achieves the lowest computational overhead by far, requiring merely ms for the entire process, which is achieved by strategically eliminating redundant Chebyshev polynomial computations and optimizing the aggregate signature verification into a single streamlined step. Hence, The proposed scheme outperforms the others in terms of computational cost while ensuring security.

6.3. Communication cost

The communication cost analysis compares the proposed scheme with four related works [3033], as shown in Table 8. In the proposed work, the Chebyshev polynomial computations, modular power operations and cryptographic hash algorithms each require 256 bits (32 bytes), whereas the current timestamp consumes 32 bits (4 bytes) of memory. Parameters transmitted from the User to the include , where is computed as , involving one Chebyshev polynomial computation, one hash operation and one timestamp, totalling 544 bits (68 bytes). Similarly, I2, transmitted from to the TA, also requires 544 bits (68 bytes). During TA verification, two sets of parameters are needed to evaluate the and , resulting in a total communication cost of 1024 bits (128 bytes), demonstrating the scheme’s efficiency in minimizing communication overhead while maintaining robust security.

thumbnail
Table 8. Comparison of communication overhead with other schemes.

https://doi.org/10.1371/journal.pone.0357045.t008

In comparison, the complete authentication process according to Al Shareeda et al. [33] involves identity (20 bytes), the output of the Chebyshev polynomial (32 bytes), the hash value (20 bytes) and the timestamp (4 bytes). So, in total it comes around 76 bytes. The final communication cost includes Vehicle to Fog server, Fog server to Trusted Authority, Trusted Authority to Fog server and final Fog server to Vehicle. The final communication comes around bytes. Tomar et al. [32] incur 236 bytes between Fog server and the vehicle. In addition, 384 bytes were used between the cloud and fog servers, summing to 620 bytes. Jie Cui et al. [31] requires 96 bytes for vehicle-to-TA communication, 96 bytes for UAV-to-TA, and 172 bytes for TA-to-UAV and TA-to-vehicle, so the total communication overhead needed is 364 bytes. Jiyun Yang et al. [30] achieves the lowest cost of 84 bytes by transmitting only these parameters .

To accurately evaluate the communication efficiency of our proposed protocol, we compute the total end-to-end communication cost by analyzing the bit-length requirements of each transmitted message across the three sequential phases. As summarized in Fig 6, our scheme achieves a communication cost of 264 bytes. In our scheme, all cryptographic primitives including Chebyshev polynomial outputs, hash function outputs, and modular power operations are 256 bits (32 bytes) in size, while the timestamp is 32 bits (4 bytes).

thumbnail
Fig 6. Comparison of communication overhead (bytes) for 1 to 100 vehicles with other schemes..

https://doi.org/10.1371/journal.pone.0357045.g006

The detailed breakdown is as follows:

  • Phase 1 (User to RSU): The transmitted message is , where represents a hash output. This phase incurs a cost of Chebyshev polynomial (32 bytes) + Hash (32 bytes) + Timestamp (4 bytes) = 68 bytes.
  • Phase 2 (RSU to TA): The message I2 follows an identical structure to Phase 1, contributing another 68 bytes.
  • Phase 3 (TA Verification): The TA performs verification using two sets of parameters: for the RSU, and for the vehicle, where and are nonces of 32 bytes each. This phase collectively costs E1 (32 bytes) + (32 bytes) + E2 (32 bytes) + (32 bytes) = 128 bytes.

Therefore, the total communication overhead of our proposed scheme is 68 + 68 + 128 = 264 bytes.

As summarized in Table 8, our scheme achieves a communication cost of 264 bytes, which, while marginally higher than Jiyun Yang et al. [30] (84 bytes), significantly outperforms Jie Cui et al. [31] (364 bytes), Tomar et al. [32] (620 bytes), and Shareeda et al. [33] (304 bytes). This demonstrates that our protocol strikes an effective balance by minimizing communication overhead while maintaining robust security guarantees.

6.4. Storage overhead analysis

Storage overhead is an important performance metric for authentication protocols in VANETs, since On-Board Units (OBUs) and Roadside Units (RSUs) maintain very limited memory resources. Therefore, an efficient authentication protocol should minimize the amount of information stored by each participating entity while preserving the required security properties. This subsection analyzes the storage requirements of the proposed authentication protocol for the vehicle, RSU, and Trusted Authority (TA). To evaluate the storage analysis, the notations and parameter sizes considered in this work are summarized in Table 9.

thumbnail
Table 9. Notation and Size of Stated Parameters.

https://doi.org/10.1371/journal.pone.0357045.t009

The size of the Chebyshev parameter depends on the selected prime modulus P. In this work, a 160-bit parameter is considered for the storage overhead analysis.

Vehicle Storage: After the registration phase, each vehicle stores its real identity (), dummy identity (), private key (), and public key (). Following a successful mutual authentication with the RSU, the vehicle additionally stores the negotiated session key (), which is used to secure subsequent communications. Therefore, the storage overhead of the vehicle can be expressed as:

(49)

RSU Storage: Similarly, each RSU stores its real identity (), dummy identity (), private key (), and public key (). After completing the authentication process, the RSU also stores the negotiated session key () for secure communications with authenticated vehicles. Consequently, the storage overhead of the RSU is given by:

(50)

Since both the vehicle and the RSU maintain the same set of authentication credentials and session information, their storage requirements are identical.

Trusted Authority Storage: The Trusted Authority (TA) maintains its master private key (b) together with the registration database of all participating entities. For each registered vehicle, the TA stores the corresponding real identity, dummy identity, private key, and public key, namely the tuple . Likewise, for every registered RSU, the TA stores the tuple .

If the network contains N registered vehicles and M registered RSUs, the storage overhead at the TA is expressed as:

(51)

Using the parameter sizes listed in Table 9, the storage overhead of each entity is summarized in Table 10.

thumbnail
Table 10. Summary of Storage Overhead Per Entity.

https://doi.org/10.1371/journal.pone.0357045.t010

Therefore, the total storage requirement of the TA for a network containing N registered vehicles and M registered RSUs is

(52)

The above analysis demonstrates that the proposed protocol imposes only 896 bits(112 bytes)of storage overhead on both the vehicle and the RSU, which is relatively small for modern vehicular hardware. The primary storage burden resides at the TA because it maintains the registrations database and identifies mapping for all participating entities. Since the TA is assumed to possess sufficient computational and storage resources, this centralized storage requirement does not affect the practicality or scalability of the proposed authentication protocol, Furthermore, the protocol does not require certificate repositories, verification tables, or additional authentication databases at either the vehicle or the RSU, making it well suited for resource constrained VANET environments

6.5. Performance comparison of chebyshev polynomials with ECC and Lattice-Based Models

To evaluate the efficiency of the proposed scheme, Table 11 compares the proposed Chebyshev polynomial-based scheme with existing works [3437]. Zhu et al. [34] scheme incurs 12.231 ms due to scalar multiplications and pairings. Yang et al. [35] require 13.383 ms because of modular exponentiations, inversions and pairings. Liu et al. [36] present the most expensive scheme at 36.227 ms with complex multi-key and multi-matrix operations, unsuitable for latency-sensitive VANETs. Lil et al. [37] take 12.24 ms. This is moderate efficiency. They use matrix-vector operations. But this time is still higher than lightweight methods. Our proposed scheme is much faster. It completes authentication in just 0.949468 ms. It uses only hash functions and Chebyshev polynomial operations. This results in the lowest computational cost. So, our scheme proves that it is highly suitable for real-time VANET applications.

thumbnail
Table 11. Comparison of Chebyshev vs Non-Chebyshev Schemes.

https://doi.org/10.1371/journal.pone.0357045.t011

The proposed protocol offers three main advantages.

  1. Our design never uses bilinear pairings. This act minimizes execution time.
  2. We never use ECC operations; this act reduces scalar multiplications from three to two. That is a 33% reduction. This results in improved scalability.
  3. We compare with lattice-based models [35,36]; it results in less communication cost when compared with others. It is practical for real deployment. It also works well in large and fast moving environments.

Table 6 represents the notations and descriptions of cryptographic and matrix operations. These parameters are used to calculate computational costs for existing schemes [3437] in Table 11. It gives the notation details and the list of notations and their corresponding descriptions which are used in earlier sections.

Fig 7 represents a comparative bar graph of total execution time (in milliseconds) for the proposed Chebyshev-based scheme vs ECC-based and lattice-based cryptographic models. The proposed scheme outperforms both categories, achieving 0.949468 ms total cost. ECC-based schemes typically range from 10 to 15 ms, while lattice-based schemes [36, 37] require substantially higher overhead (12–37 ms) because of large matrix and vector operations. Our scheme achieves a remarkably low total execution time of just ms, which is substantially lower than all competing schemes across both cryptographic paradigms. Specifically, when compared to the ECC-based schemes, our approach demonstrates a improvement over Zhu et al. [36] (12.231 ms) and a improvement over Yang et al. [37] (13.383 ms). The superiority of our scheme is even more pronounced against the lattice-based schemes, where we achieve a improvement over Liu et al. [29] (36.227 ms) and an outstanding improvement over Li et al. [28] (12.024 ms).

thumbnail
Fig 7. Comparative analysis of the proposed method versus ECC and lattice-based models.

https://doi.org/10.1371/journal.pone.0357045.g007

6.6. RSU Servicing Capability Analysis in VANET Environments

This section evaluates an RSU. The RSU can send signals up to 300 meters. This is a normal VANET with DSRC. We study two limits. One is how many authentications it can do. Two is the wireless channel. Table 12 lists the real-world system parameters for RSU servicing capability analysis in a DSRC-based VANET scenario.

thumbnail
Table 12. Parameters Used for RSU Servicing Capability Analysis in a DSRC-Based VANET Scenario.

https://doi.org/10.1371/journal.pone.0357045.t012

6.7. Key computations

Bitrate Demand Per Vehicle: Every vehicle transmits messages per second, each of size :

(53)

Channel Capacity with Efficiency: Let be the channel efficiency, modelled as a function of speed v (km/h):

(54)

Then the effective channel capacity is:

(55)(56)

Authentication Limit: The number of authentications the RSU can perform per second is:

(57)

Area: For a coverage radius R, the area is:

(58)

For traffic density (vehicles/km2):

(59)

Final Servicing Capability: The actual number of vehicles the RSU can support is:

(60)

Where is the number of vehicles present.

Fig 8 illustrates the 3D grouped column chart for RSU (Roadside Unit) servicing capability as a function of vehicle density and channel efficiency in VANETs. The chart represents the number of vehicles that can be authenticated and served per second under three different channel efficiencies: 60% (cap = 375 vehicles/sec), 50% (cap = 312.5 vehicles/sec) and 40% (cap = 250 vehicles/sec). The X-axis shows increasing vehicle density (50–600 vehicles), the Y-axis corresponds to the RSU servicing capability (vehicles per second) and coloured bars indicate performance under each channel efficiency scenario.

thumbnail
Fig 8. RSU Authentication and Service Rate vs. Vehicle Density under Varying Channel Efficiency Conditions.

https://doi.org/10.1371/journal.pone.0357045.g008

Major observations:

  • At low vehicle densities (<100), the RSU can serve all vehicles across all speeds.
  • At medium densities (200–400), the channel becomes a limiting factor at higher speeds (due to reduced efficiency).
  • At high densities (500–600 vehicles), channel capacity saturates, limiting the number of vehicles served, even though cryptographic capacity remains underutilized.
  • The RSU CPU can handle over 31,000 auth/sec, so communication, not computation, is the primary bottleneck.

7. Analysis by NS-3 simulations

The proposed protocol was integrated into the NS-3 framework by modelling the authentication message exchange (D1, D2, D3, D4) as part of the application layer traffic. The computational delay for cryptographic operations presented in Table 6 was incorporated using a custom delay model to ensure realistic timing.

7.1. Packet Delivery Ratio (PDR)

PDR is calculated as the ratio of the number of data packets successfully delivered to the destination to the number of packets generated by the source. Table 13 shows the simulation environment configuration parameters. The table lists all relevant settings including mobility model, network topology, vehicle density, transmission range and channel characteristics. It is observed that PDR slightly decreases from 98.5% to 92% when the vehicle density increases from 20 to 120. So, the PDR is always above 92 percent as shown in Fig 9a. This is true for 120 vehicles too. Too many vehicles cause network congestion. This may also cause packet collisions because of too many packets in transmission. Our handshake methodology is so light. It does not add too many control packets. So, the performance remains good.

thumbnail
Fig 9. a) Packet delivery ratio, b) Throughput, c) End-to-end delay.

https://doi.org/10.1371/journal.pone.0357045.g009

7.2. Throughput

Throughput shows that more vehicles mean more throughput. In other words, the total amount of data successfully delivered to all the destination vehicles per unit of time. It is evident that throughput increases from 220 Kbps to 950 Kbps as more vehicles generate and forward data. Even though the individual packet delivery ratio drops slightly, the throughput does not change, as shown in Fig 9b.

7.3. End-to-end delay

This measure depicts the average travel time for a data packet. The packet goes from the source vehicle to the destination. The destination could be TA, user or RSU. This delay (as shown in Fig 9c) includes queuing delay, propagation delay, transmission delay and authentication processing delay. It is observed that the delay increases from 48 ms to 125 ms when the number of vehicles grows. It shows that they also have more queuing delays. Cryptographic operations add some standard fixed delay. This is a good trade-off for security.

The simulation results confirm our protocol is secure. It is also efficient and practical for real VANETs. The overhead is manageable. So, network performance stays strong even when the network grows.

8. Limitations and future work

In our scheme, some real messages with high latency may be rejected because their timestamps fall outside the window. Future work will fix this. We will use an adaptive tolerance range that can accept vehicles up to that range. It will change accordingly with network conditions. This will minimize false rejections but keep security. We will also study a blockchain-based TA for VANETs to make distributed TA services for decentralized key management. However, this paper does not study the distributed TA. The single point of failure remains unsolved. We leave this for the future scope.

9. Conclusion

In this article, we presented a novel anonymous authentication model using Chebyshev polynomials and a chaotic map, along with a normal matrix-based binary exponentiation algorithm. The proposed method handles the security challenges of VANETs, which come from their open and dynamic nature, by enabling efficient and secure Chebyshev polynomial calculations. Our scheme achieved 0.949468 ms execution time and 264 bytes of communication overhead. We used Scyther for formal verification. All 17 security claims are OK. This proves mutual authentication works, it proves key secrecy works, and it also proves replay attack resistance works. According to the theoretical study in our scheme, RSU can process 31,000 vehicles per second. Due to the practical density limit of the DSRC channel, each RSU can process 400 vehicles. We developed a fast authentication scheme specifically for VANETs, which reduces both computational and communication costs by using lightweight Chebyshev polynomials and hash functions during authentication and key agreement processes. This makes our approach more efficient than current framework solutions. As part of our future work, we intend to evaluate the energy consumption and resource utilization of the proposed authentication protocol through implementation on representative vehicular hardware and realistic VANET simulation environments. Moreover, we intend to evaluate the scalability of the proposed authentication protocol under high vehicle density and large-scale VANET environments through extensive simulations and real-world traffic scenarios.

References

  1. 1. Ministry of Road Transport and Highways. Road Accident in India. https://morth.nic.in/road-accident-in-india
  2. 2. World Health Organization. Global status report on road safety 2023. 2023. https://www.who.int/teams/social-determinants-of-health/safety-and-mobility/global-status-report-on-road-safety-2023
  3. 3. Zhang J, Cui J, Zhong H, Chen Z, Liu L. PA-CRT: Chinese Remainder Theorem Based Conditional Privacy-Preserving Authentication Scheme in Vehicular Ad-Hoc Networks. IEEE Trans Dependable and Secure Comput. 2021;18(2):722–35.
  4. 4. Vasudev H, Das D. P-SHARP: Privacy Preserving Secure Hash based Authentication and Revelation Protocol in IoVs. Computer Networks. 2021;191:107989.
  5. 5. Wang Y, Liu Y, Tian Y. ISC-CPPA:Improverd-Security Certificateless Conditional Privacy-Preserving Authentication Scheme With Revocation. IEEE Trans Veh Technol. 2022;71(11):12304–14.
  6. 6. Zhou X, He D, Khan MK, Wu W, Choo K-KR. An Efficient Blockchain-Based Conditional Privacy-Preserving Authentication Protocol for VANETs. IEEE Trans Veh Technol. 2023;72(1):81–92.
  7. 7. Sang G, Chen J, Liu Y, Wu H, Zhou Y, Jiang S. PACM: Privacy-Preserving Authentication Scheme With on-Chain Certificate Management for VANETs. IEEE Trans Netw Serv Manage. 2023;20(1):216–28.
  8. 8. Cheng Y, Ma J, Liu Z, Wang L, Ying Z, Chen X. Efficient Anonymous Authentication and Privacy-Preserving Reliability Evaluation for Mobile Crowdsensing in Vehicular Networks. IEEE Internet Things J. 2023;10(17):14925–39.
  9. 9. Cheng T, Liu Q, Shi Q, Yang Z, Wang C, Zhang X, et al. Efficient Anonymous Authentication and Group Key Distribution Scheme Based on Quantum Random Numbers for VANETs. IEEE Internet Things J. 2024;11(13):23544–60.
  10. 10. Yang W, Fan J, Song K, Zheng Y, Zhang F. An Efficient and Practical Conditional Privacy-Preserving Aggregate Authentication for Vehicular Ad-Hoc Networks. IEEE Trans Intell Transport Syst. 2024;25(12):20256–67.
  11. 11. Baee MAR, Simpson L, Boyen X, Foo E, Pieprzyk J. A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected Vehicles. IEEE Trans Dependable and Secure Comput. 2024;21(4):4066–83.
  12. 12. Cheong C, Song Y, Cao Y, Zhang Y, Cai B, Ni Q. Multidimensional Trust Evidence Fusion and Path-Backtracking Mechanism for Trust Management in VANETs. IEEE Internet Things J. 2024;11(10):18619–34.
  13. 13. Tan H, Zheng W, Guan Y, Lu R. A Privacy-Preserving Attribute-Based Authenticated Key Management Scheme for Accountable Vehicular Communications. IEEE Trans Veh Technol. 2023;72(3):3622–35.
  14. 14. Lin C, Huang X, He D. EBCPA: Efficient Blockchain-based Conditional Privacy-preserving Authentication for VANETs. IEEE Trans Dependable and Secure Comput. 2022;:1–1. https://doi.org/10.1109/tdsc.2022.3164740
  15. 15. Liang Y, Liu Y. Analysis and Improvement of an Efficient Certificateless Aggregate Signature With Conditional Privacy Preservation in VANETs. IEEE Systems Journal. 2023;17(1):664–72.
  16. 16. Bojjagani S, Reddy YCAP, Anuradha T, Rao PVV, Reddy BR, Khan MK. Secure Authentication and Key Management Protocol for Deployment of Internet of Vehicles (IoV) Concerning Intelligent Transport Systems. IEEE Trans Intell Transport Syst. 2022;23(12):24698–713.
  17. 17. Mansour A, Malik KM, Alkaff A, Kanaan H. ALMS: Asymmetric Lightweight Centralized Group Key Management Protocol for VANETs. IEEE Trans Intell Transport Syst. 2021;22(3):1663–78.
  18. 18. Madani B, Azzaz M salah, Sadoudi S, Kaibou R. Fast and efficient hardware architecture of Chebyshev polynomials algorithm for resisting to side channel attacks. J Supercomput. 2024;81(1).
  19. 19. Singh R, Sturley S, Tewari H. Blockchain-Enabled Chebyshev Polynomial-Based Group Authentication for Secure Communication in an Internet of Things Network. Future Internet. 2023;15(3):96.
  20. 20. Zhang L, Zhu Y, Ren W, Wang Y, Choo K-KR, Xiong NN. An Energy-Efficient Authentication Scheme Based on Chebyshev Chaotic Map for Smart Grid Environments. IEEE Internet Things J. 2021;8(23):17120–30.
  21. 21. Seifelnasr M, AlTawy R, Youssef A. A Conditional Privacy-Preserving Protocol for Cross-Domain Communications in VANET. IEEE Trans Intell Transport Syst. 2025;26(4):5251–63.
  22. 22. Wang C, Wang C, Shen J, Vasilakos AV, Wang B, Wang W. Efficient Batch Verification and Privacy-Preserving Data Aggregation Scheme in V2G Networks. IEEE Trans Veh Technol. 2025;74(8):12029–41.
  23. 23. Vangujar AK, Umrani A, Palmieri P. Identity-based cluster authentication and key exchange (ID-CAKE) message broadcasting and batch verification in VANETs. In: Lecture Notes in Computer Science; 2024. p. 162–79.
  24. 24. Krishnan P, Jain K, Alluhaidan A-SD, Prabu P. Highly secured authentication and fast handover scheme for mobility management in 5G vehicular networks. Computers and Electrical Engineering. 2024;116:109152.
  25. 25. Bergamo P, D’Arco P, De Santis A, Kocarev L. Security of public-key cryptosystems based on Chebyshev polynomials. IEEE Trans Circuits Syst I. 2005;52(7):1382–93.
  26. 26. Lima JB, Campello de Souza RM, Panario D. Security of public-key cryptosystems based on Chebyshev polynomials over prime finite fields. In: 2008 IEEE International Symposium on Information Theory, 2008. 1843–7. https://doi.org/10.1109/isit.2008.4595307
  27. 27. Zhu H, Zhang Y, Xia Y, Li H. Password-authenticated key exchange scheme using chaotic maps towards a new architecture in standard model. International Journal of Network Security. 2016;18(2):326–34.
  28. 28. Bodei C, Degano P, Nielson F, Riis Nielson H. Flow logic for Dolev–Yao secrecy in cryptographic processes. Future Generation Computer Systems. 2002;18(6):747–56.
  29. 29. Backes M. Real-or-random Key Secrecy of the Otway-Rees Protocol via a Symbolic Security Proof. Electronic Notes in Theoretical Computer Science. 2006;155:111–45.
  30. 30. Yang J, Deng J, Xiang T, Tang B. A Chebyshev polynomial-based conditional privacy-preserving authentication and group-key agreement scheme for VANET. Nonlinear Dynamics. 2021;106(3):2655–66.
  31. 31. Cui J, Liu X, Zhong H, Zhang J, Wei L, Bolodurina I, et al. A Practical and Provably Secure Authentication and Key Agreement Scheme for UAV-Assisted VANETs for Emergency Rescue. IEEE Trans Netw Sci Eng. 2024;11(2):1454–68.
  32. 32. Tomar A, Tripathi S. A Chebyshev Polynomial-Based Authentication Scheme Using Blockchain Technology for Fog-Based Vehicular Network. IEEE Trans on Mobile Comput. 2024;23(10):9075–89.
  33. 33. Al-Shareeda MA, Gaber T, Alqarni MA, Alkinani MH, Almazroey AA, Almazroi AA. Chebyshev Polynomial Based Emergency Conditions With Authentication Scheme for 5G-Assisted Vehicular Fog Computing. IEEE Trans Dependable and Secure Comput. 2025;22(5):4795–812.
  34. 34. Zhu D, Guan Y. Secure and Lightweight Conditional Privacy-Preserving Identity Authentication Scheme for VANET. IEEE Sensors J. 2024;24(21):35743–56.
  35. 35. Yang X, Li S, Yang L, Du X, Wang C. Efficient and Security-Enhanced Certificateless Aggregate Signature-Based Authentication Scheme With Conditional Privacy Preservation for VANETs. IEEE Trans Intell Transport Syst. 2024;25(9):12256–68.
  36. 36. Liu G, Li H, Le J, Wang N, Liu Y, Xiang T. LRCPA: Lattice-Based Robust and Conditional Privacy-Preserving Authentication for VANETs. IEEE Trans Veh Technol. 2025;74(3):4698–712.
  37. 37. Li L, Hsu C, Ho Au M, Cui J, Harn L, Zhao Z. Lattice-Based Conditional Privacy-Preserving Batch Authentication Protocol for Fog-Assisted Vehicular Ad Hoc Networks. IEEE TransInformForensic Secur. 2024;19:9629–42.