Yan-hua Liang, Zhiguo Wan, Yiming Chen, Zhiqiang Zhao, Gao Liu, Zhiquan Liu, Hong Sun, Yining Liu
Abstract
The emergence of Vehicular Ad Hoc Networks (VANETs) has revolutionized modern transportation by enabling real-time and cooperative communication between vehicles and infrastructure. However, vehicular interactions operate across two layers: human–vehicle access and vehicle–network communication. This dual-layered nature introduces complex security and privacy challenges. Existing Conditional Privacy-Preserving Authentication (CPPA) schemes mainly focus on message-level anonymity and integrity. However, they often overlook systemic vulnerabilities across the entire trust lifecycle. These limitations include the inability to verify driver legitimacy during vehicle access, high computational overhead due to heavyweight cryptographic primitives, the lack of password update and recovery mechanisms, and insufficient resistance to physical key extraction attacks. To address these issues, we propose VLCADA, a Vehicle-side Lightweight Conditional Anonymous Double Authentication framework. VLCADA establishes a vertically integrated security architecture for intelligent vehicles. It unifies multi-factor driver authentication with efficient and conditionally anonymous message authentication. At the access layer, VLCADA combines identity–password credentials, biometric verification, and Physical Unclonable Functions (PUF). This ensures that only legitimate users can access and control the vehicle. At the communication layer, we design a Signer-side Lightweight Conditional Anonymous Signature (SLCAS) scheme. This scheme shifts computationally intensive operations to an offline phase, leaving only lightweight hash and XOR operations during real-time execution. In addition, we propose a Dynamic Password Mechanism (DPM) based on threshold secret sharing. This mechanism enables secure password update and recovery without trusted authority intervention. Furthermore, by integrating PUF with fuzzy extractors, VLCADA effectively mitigates noise and provides resistance against physical attacks. Comprehensive security analysis shows that VLCADA satisfies essential security requirements. Experimental results demonstrate that VLCADA reduces total computational overhead by up to 48.55% and communication cost by up to 32.61% compared with state-of-the-art schemes.
Citation format
LIANG, Yan-hua, et al. Vehicle-side lightweight conditional anonymous double authentication framework with password robustness in VANETs. IEEE Transactions on Dependable and Secure Computing, 2026.