跳到主要內容

簡易檢索 / 詳目顯示

研究生: 王昱翔
Wang, Yu-Siang
論文名稱: 以執法機關車輛作為領導車輛於市區場景之車聯網假名變更策略
A Pseudonym Change Strategy for Vehicular Networks in Urban Scenarios Using Law Enforcement Vehicles as Lead Vehicles
指導教授: 孫士勝
Sun, Shi-Sheng
口試委員: 高大宇
左瑞麟
蔡孟勳
孫士勝
學位類別: 碩士
Master
系所名稱: 資訊學院 - 資訊科學系碩士在職專班
Excutive Master Program of Computer Science
論文出版年: 2026
畢業學年度: 115
語文別: 中文
論文頁數: 97
中文關鍵詞: 車聯網位置隱私假名變更策略混合區智慧型運輸系統執法機關車輛廣播和靜默期
外文關鍵詞: V2X Location Privacy, Pseudonym Change Strategy, Mix Zone, Intelligent Transportation Systems (ITS), Law Enforcement Vehicle, Broadcast and Silence Period (BSP)
相關次數: 點閱:30下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著車聯網(V2X,Vehicle-to-Everything)與智慧型運輸系統(ITS,Intelligent Transportation Systems)的發展,車輛會週期性廣播基本安全訊息(BSM,Basic Safety Message),提供位置、速度與方向等行車狀態,以提升行車安全;車輛並以假名憑證(Pseudonym Certificate)所對應的私鑰對BSM進行數位簽章,使周遭車輛得以驗證訊息來源與完整性。然而,全域被動攻擊者(GPA,Global Passive Adversary)可能長期側錄訊息,透過語法或語義鏈結,將假名變更前後的訊息重新關聯,造成位置隱私外洩。固定地點式或固定週期式假名變更策略較難因應市區交通與執法任務的即時變化,靜默時機不當亦可能影響安全通訊。本研究聚焦市區路口的執法與緊急勤務情境,提出以執法機關車輛(以下簡稱執法車輛)作為領導車輛的動態假名變更策略。系統由可信任授權中心(TA,Trusted Authority)、路側單元(RSU,Roadside Unit)與車載單元(OBU,On-Board Unit)協同運作,依執法車輛的任務路徑選定候選混合區(Mix Zone),並由RSU透過廣播和靜默期(BSP,Broadcast and Silence Period)協調普通車輛同步換名。當執法車輛接近候選混合區所在路口,且區內符合安全條件的普通車輛數達到啟動門檻時,RSU即啟動混合區,安排普通車輛短暫靜默並切換假名,使攻擊者難以鏈結新舊假名;執法車輛則持續廣播BSM,以維持安全通訊。本研究透過Veins整合OMNeT++與SUMO建立市區模擬環境。實驗結果顯示,所提策略可增加匿名集合大小、提高平均隱私熵值、降低追蹤成功率,並提升執法車輛的通行效率,而普通車輛平均速度未明顯下降。研究成果可作為未來智慧型運輸系統兼顧位置隱私、安全通訊與緊急通行需求之參考。


    With the development of Vehicle-to-Everything (V2X) and Intelligent Transportation Systems (ITS), vehicles periodically broadcast Basic Safety Messages (BSMs) carrying driving status such as position, speed, and heading in order to improve driving safety. Each vehicle signs its BSMs with the private key corresponding to its pseudonym certificate, so that surrounding vehicles can verify the origin and integrity of the messages. However, a Global Passive Adversary (GPA) may eavesdrop on these messages over long periods and, through syntactic or semantic linking, re-associate the messages sent before and after a pseudonym change, thereby leaking a vehicle's location privacy. Fixed-location or fixed-interval pseudonym-change strategies adapt poorly to the real-time variations of urban traffic and law-enforcement missions; an ill-timed silence period may further undermine safety-critical communication. Focusing on law-enforcement and emergency-service scenarios at urban intersections, this study proposes a dynamic pseudonym-change strategy that uses a law enforcement vehicle (LEV) as the lead vehicle. In the proposed system, the Trusted Authority (TA), Roadside Units (RSUs), and On-Board Units (OBUs) operate cooperatively: candidate Mix Zones are selected according to the LEV’s mission route, and the RSU coordinates synchronized pseudonym changes among the regular vehicles through a Broadcast and Silence Period (BSP) schedule. When the LEV approaches the intersection where a candidate Mix Zone is located and the number of regular vehicles in the zone satisfying the safety conditions reaches the activation threshold, the RSU activates the Mix Zone and schedules a brief silence period and a pseudonym switch for those vehicles, making it difficult for the adversary to link the old and new pseudonyms; the LEV itself keeps broadcasting BSMs so that safety-critical communication is preserved. This study builds an urban simulation environment with Veins, which integrates OMNeT++ and SUMO. The experimental results show that the proposed strategy increases the anonymity-set size, raises the average privacy entropy, reduces the tracking success rate, and improves the passage efficiency of the LEV, while the average speed of regular vehicles does not decrease significantly. These findings can serve as a reference for future intelligent transportation systems that must balance location privacy, safety-critical communication, and emergency-passage needs.

    致謝 I
    摘要 II
    Abstract III
    目次 V
    圖次 VII
    表次 VIII
    第一章 緒論 1
    第一節 研究背景與問題概述 1
    第二節 車聯網假名變更與隱私挑戰 3
    第三節 研究動機與問題意識 5
    第四節 研究目標與貢獻 9
    第五節 論文架構 13
    第二章 相關研究 15
    第一節 車聯網位置隱私與假名機制 15
    第二節 假名憑證與安全管理架構 18
    第三節 混合區與假名變更策略 21
    第四節 BSP策略 24
    第五節 綜合比較與本研究定位 28
    第三章 系統模型與BSP假名變更機制 33
    第一節 系統架構與角色定義 33
    第二節 威脅模型與研究假設 36
    第三節 BSM通訊與狀態模型 39
    第四節 混合區與BSP時空模型 43
    第五節 問題定義與設計目標 47
    第四章 以執法車輛為領導車輛之假名變更方法 50
    第一節 方法概觀與設計原則 50
    第二節 路徑導向之候選混合區選擇 52
    第三節 執法車輛觸發與匿名集合判定 53
    第四節 BSP排程與假名切換流程 54
    第五節 混合區解除與恢復機制 56
    第六節 演算法偽程式碼 57
    第五章 實驗設計與效能評估 66
    第一節 模擬環境與實驗設定 66
    第二節 實驗參數與比較基準 68
    第三節 隱私保護效果分析 73
    第四節 執法車輛任務效率與交通影響分析 80
    第五節 綜合討論 84
    第六章 結論與未來工作 87
    第一節 研究結論 87
    第二節 研究限制與未來研究方向 90
    參考文獻 93

    [1] H. Li, Y. Lai, and Y. Chen, “Broadcast and Silence Period (BSP): A Pseudonym Change Strategy,” IEEE Trans. Veh. Technol., vol. 72, no. 10, pp. 13618–13630, Oct. 2023, doi: 10.1109/TVT.2023.3279121.
    [2] Z. Lu, G. Qu, and Z. Liu, “A Survey on Recent Advances in Vehicular Network Security, Trust, and Privacy,” IEEE Trans. Intell. Transport. Syst., vol. 20, no. 2, pp. 760–776, Feb. 2019, doi: 10.1109/TITS.2018.2818888.
    [3] F. Chbib, S. Zeadally, A. Fadlallah, R. Khatoun, and A. E. Attar, “Tracking Vehicles in Cooperative Intelligent Transportation Systems: Attacks, Defense Solutions, and Future Directions,” IEEE Trans. Intell. Transport. Syst., vol. 26, no. 10, pp. 14615–14635, Oct. 2025, doi: 10.1109/TITS.2025.3581355.
    [4] A. Alshaeri and M. Younis, “Certificate-Less Single-Use Pseudonym Scheme for Countering Trajectory Tracking Attacks in ITS,” IEEE Trans. Intell. Transport. Syst., vol. 26, no. 7, pp. 9214–9225, Jul. 2025, doi: 10.1109/TITS.2025.3568290.
    [5] A. Boualouache, S.-M. Senouci, and S. Moussaoui, “A Survey on Pseudonym Changing Strategies for Vehicular Ad-Hoc Networks,” IEEE Commun. Surv. Tutorials, vol. 20, no. 1, pp. 770–790, 2018, doi: 10.1109/COMST.2017.2771522.
    [6] G. G. Zoccoli, F. Valgimigli, D. Stabili, and M. Marchetti, “RADAR: a Radio-based Analytics for Dynamic Association and Recognition of pseudonyms in VANETs,” in 2025 IEEE 102nd Vehicular Technology Conference (VTC2025-Fall), Chengdu, China: IEEE, Oct. 2025, pp. 1–7. doi: 10.1109/VTC2025-Fall65116.2025.11310197.
    [7] X. Li et al., “PAPU: Pseudonym Swap With Provable Unlinkability Based on Differential Privacy in VANETs,” IEEE Internet Things J., vol. 7, no. 12, pp. 11789–11802, Dec. 2020, doi: 10.1109/JIOT.2020.3001381.
    [8] Intelligent Transportation Systems Committee, “IEEE Standard for Wireless Access in Vehicular Environments (WAVE)—Certificate Management Interfaces for End Entities,” IEEE Std 1609.2.1-2022, IEEE, Piscataway, NJ, USA, 2022.
    [9] B. Brecht et al., “A Security Credential Management System for V2X Communications,” IEEE Trans. Intell. Transport. Syst., vol. 19, no. 12, pp. 3850–3871, Dec. 2018, doi: 10.1109/TITS.2018.2797529.
    [10] 黃政嘉等人, “車聯網資安通訊架構研析,” 財團法人中華顧問工程司, 臺北市, 臺灣, 期末報告, Apr. 2023.
    [11] L. Wang, Y. Lai, and C. Zeng, “ADMZ: Adaptive Dynamic Mix Zone pseudonym change strategy for location privacy in Vehicular Ad-hoc Networks,” Ad Hoc Networks, vol. 181, p. 104066, Feb. 2026, doi: 10.1016/j.adhoc.2025.104066.
    [12] A. Boualouache, S.-M. Senouci, and S. Moussaoui, “VLPZ: The Vehicular Location Privacy Zone,” Procedia Computer Science, vol. 83, pp. 369–376, 2016, doi: 10.1016/j.procs.2016.04.198.
    [13] R. Lu, X. Lin, T. H. Luan, X. Liang, and X. Shen, “Pseudonym Changing at Social Spots: An Effective Strategy for Location Privacy in VANETs,” IEEE Trans. Veh. Technol., vol. 61, no. 1, pp. 86–96, Jan. 2012, doi: 10.1109/TVT.2011.2162864.
    [14] A. Boualouache and S. Moussaoui, “TAPCS: Traffic-aware pseudonym changing strategy for VANETs,” Peer-to-Peer Netw. Appl., vol. 10, no. 4, pp. 1008–1020, Jul. 2017, doi: 10.1007/s12083-016-0461-4.
    [15] Y. Li, Y. Yin, X. Chen, J. Wan, G. Jia, and K. Sha, “A Secure Dynamic Mix Zone Pseudonym Changing Scheme Based on Traffic Context Prediction,” IEEE Trans. Intell. Transport. Syst., vol. 23, no. 7, pp. 9492–9505, Jul. 2022, doi: 10.1109/TITS.2021.3125744.
    [16] Z. Zhang, T. Feng, W.-C. Wong, and B. Sikdar, “A Geo-Indistinguishable Context-Based Mix Strategy for Trajectory Protection in VANETs,” IEEE Trans. Veh. Technol., vol. 72, no. 12, pp. 16538–16552, Dec. 2023, doi: 10.1109/TVT.2023.3293127.
    [17] C. Zhao, Y. Yang, X. Deng, X. Ge, and H. Li, “A Vehicle-Centric Pseudonym Change and Management Scheme for Location Privacy Preserving in VANETs,” in 2025 IEEE Smart World Congress (SWC), Calgary, AB, Canada: IEEE, Aug. 2025, pp. 1244–1249. doi: 10.1109/SWC65939.2025.00197.
    [18] A. Hayat, Z. Iftikhar, M. I. Khan, A. Mehbodniya, J. L. Webber, and S. Hanif, “A Novel Pseudonym Changing Scheme for Location Privacy Preservation in Sparse Traffic Areas,” IEEE Access, vol. 11, pp. 89974–89985, 2023, doi: 10.1109/ACCESS.2023.3303846.
    [19] A. P. Mdee, M. T. R. Khan, J. Seo, and D. Kim, “Security Compliant and Cooperative Pseudonyms Swapping for Location Privacy Preservation in VANETs,” IEEE Trans. Veh. Technol., vol. 72, no. 8, pp. 10710–10723, Aug. 2023, doi: 10.1109/TVT.2023.3254660.
    [20] Y. Wu, “TCCM: Trajectory Converged Chaff-Based Mix-Zone Strategy for Enhancing Location Privacy in VANET,” IEEE Access, vol. 13, pp. 45436–45448, 2025, doi: 10.1109/ACCESS.2025.3550442.
    [21] J. Wang, Y. Sun, and C. Phillips, “Fake Beacon: A Pseudonym Changing Scheme for Low Vehicle Density in VANETs,” in 2023 IEEE 97th Vehicular Technology Conference (VTC2023-Spring), Florence, Italy: IEEE, Jun. 2023, pp. 1–7. doi: 10.1109/VTC2023-Spring57618.2023.10199627.
    [22] B. Ying, D. Makrakis, and H. T. Mouftah, “Dynamic Mix-Zone for Location Privacy in Vehicular Networks,” IEEE Commun. Lett., vol. 17, no. 8, pp. 1524–1527, Aug. 2013, doi: 10.1109/LCOMM.2013.070113.122816.
    [23] Leping Huang, K. Matsuura, H. Yamane, and K. Sezaki, “Enhancing wireless location privacy using silent period,” in IEEE Wireless Communications and Networking Conference, 2005, New Orleans, LA, USA: IEEE, 2005, pp. 1187–1192. doi: 10.1109/WCNC.2005.1424677.
    [24] L. Benarous, S. Bitam, and A. Mellouk, “CSLPPS: Concerted Silence-Based Location Privacy Preserving Scheme for Internet of Vehicles,” IEEE Trans. Veh. Technol., vol. 70, no. 7, pp. 7153–7160, Jul. 2021, doi: 10.1109/TVT.2021.3088762.
    [25] S. Lefevre, J. Petit, R. Bajcsy, C. Laugier, and F. Kargl, “Impact of V2X privacy strategies on Intersection Collision Avoidance systems,” in 2013 IEEE Vehicular Networking Conference, Boston, MA, USA: IEEE, Dec. 2013, pp. 71–78. doi: 10.1109/VNC.2013.6737592.
    [26] J. Freudiger, M. Raya, M. Félegyházi, P. Papadimitratos, and J.-P. Hubaux, “Mix-Zones for Location Privacy in Vehicular Networks,” presented at the Proceedings of the ACM Workshop on Wireless Networking for Intelligent Transportation Systems (WiN-ITS), Vancouver, British Columbia, Canada: Association for Computing Machinery (ACM), Aug. 2007, pp. 1–7. [Online]. Available: https://infoscience.epfl.ch/bitstreams/14cbdaeb-753e-42ea-ad29-19e2c9bb0b32/download
    [27] A. Wasef and X. (Sherman) Shen, “REP: Location Privacy for VANETs Using Random Encryption Periods,” Mobile Netw Appl, vol. 15, no. 1, pp. 172–185, Feb. 2010, doi: 10.1007/s11036-009-0175-4.
    [28] K. Emara, W. Woerndl, and J. Schlichter, “CAPS: context-aware privacy scheme for VANET safety applications,” in Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks, New York New York: ACM, Jun. 2015, pp. 1–12. doi: 10.1145/2766498.2766500.
    [29] D.-H. Lee, C.-M. Kim, H.-S. Song, Y.-H. Lee, and W.-S. Chung, “Simulation-Based Cybersecurity Testing and Evaluation Method for Connected Car V2X Application Using Virtual Machine,” Sensors, vol. 23, no. 3, p. 1421, Jan. 2023, doi: 10.3390/s23031421.
    [30] N. Ravi, C. M. Krishna, and I. Koren, “Privacy and Traffic Efficiency of CAVs Under Dynamic Conditions in ITS,” IEEE Internet Things J., vol. 12, no. 24, pp. 52413–52425, Dec. 2025, doi: 10.1109/JIOT.2025.3612334.

    無法下載圖示 全文公開日期 2031/08/03
    QR CODE
    :::