Evaluation and Analysis of Standard Security Technology in V2X Communication -- Exploring ECQV Implicit Certificate Cracking
The IEEE 1609.2 and 1609.2.1 standards have used several security techniques based on elliptic curve cryptography (ECC) for vehicle-to-everything (V2X) Communication. For improving the performance of security credential management system (SCMS), this study evaluates the computation time of key generation, key expansion, signature generation, and signature verification under different security strengths. The lengths of uncompressed elliptic curve (EC) points, compressed EC points, explicit certificates, and implicit certificates based on elliptic curve Qu-Vanstone (ECQV) are analyzed and discussed. Furthermore, a mathematical model is proposed to prove the ECQV cracking probability, and suggestions are given for avoiding the potential threats of ECQV cracking.